Design and optimize large-scale SIEM architectures by integrating heterogeneous log sources, building scalable data pipelines, and developing advanced security use cases. Requires deep expertise in Cribl, SIEM platforms (Splunk/Elastic), and log processing with regex. Collaborate with cybersecurity teams to enhance detection capabilities and automate log workflows.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Capitole is one of the best IT consulting companies and the place you want to be. Why?
🤝 People in the center. We believe in a different model, more human, with the employee in the center of our company
👨 💻 Interesting projects. Cutting-edge technologies. Agile methologies
😁 Happiness and low turnover rate
🎓 €1200 per year training budget
⌚ Flexible working hours
🌏 More than 900 skilled professionals, from more than 27 nationalities
🎯 Tailored career path
📆 Monthly follow-ups. 360º continuous evaluation
🩺 Private health insurance
💰 Flexible retribution program
🏋️ ♂️ Wellhub: access to fitness, wellness, and mental health support
📄 Processing of the work permit for you to come to Spain with your family
📢 Technological communities
🥳 Lots of amazing events
📍 Location: Spain (Full Remote)
🕒 Schedule: Flexible working hours + intensive Fridays
🌍 English: C1
At Capitole Consulting we continue growing and we are looking for a Senior SIEM Data Engineer to join an international cybersecurity team working on large-scale SIEM architectures, log processing and security automation.
You will help design and optimize modern cybersecurity platforms by integrating heterogeneous log sources, building scalable data pipelines and developing advanced SIEM use cases for enterprise environments.
Searching for Data Science roles that provide visa sponsorship? Connect with international employers through Data Science Jobs with Visa Sponsorship opportunities actively seeking talented professionals.
Your responsibilities
- Connect and integrate security log sources into SIEM platforms using Cribl.
- Design parsers and normalize log data for efficient security monitoring.
- Develop and optimize log processing and routing pipelines.
- Create and document SIEM data models and security use cases.
- Participate in security assessments to identify detection opportunities.
- Improve SIEM detection capabilities and support continuous platform evolution.
- Collaborate with operations teams to automate and optimize log processing.
- Contribute to Proofs of Concept around new cybersecurity standards and technologies.
- Support incident response processes through high-quality log engineering.
Requirements
- Experience working with Cribl.
- Experience with SIEM platforms (Splunk and/or Elastic).
- Strong understanding of log ingestion, parsing and normalization.
- Experience with Regular Expressions (Regex).
- Knowledge of Security Incident Response and SIEM use cases.
- Experience with scripting (Python, Bash/Shell or JavaScript).
- Knowledge of Linux, Windows and UNIX.
- Experience with GitHub.
- Cloud knowledge in AWS, Azure and/or GCP.
- Kubernetes and/or OpenStack knowledge is a plus.
- Excellent analytical and problem-solving skills.
- English C1.
Explore our comprehensive directory of visa sponsorship jobs from employers worldwide who are ready to sponsor talented international professionals.
Nice to have
- Terraform
- Ansible
- GitHub Actions
- SIEM architecture
- Security automation
- OCSF
- SOAR platforms
- Data visualization
Want to know more? Click here 🖱️ and find out!
See what people say about us 🕵️ ♀️ Glassdoor Reviews
Feel free to send us your profile, we are excited to meet you! 💙
The employee will adhere to information security policies:
-Will have access to confidential information related to Capitole and the project they are working on.
-Must comply with the security policies and internal policies of the company and the client.
-Must sign an NDA.
Similar Jobs
Explore other opportunities that match your interests