Splunk Engineer

Mons, Belgium Deadline: 22-09-2026 Geplaatst: 08-09-2026 #17525

Role: Splunk Engineer
Location: Mons, Belgium
Working arrangement: Full-time on-site
Security clearance: NATO Secret

Primary duties

  • Serve as a principal engineer and Subject Matter Expert for SIEM and log-collection services.
  • Manage, maintain, and further develop Splunk and related data-security systems.
  • Advise stakeholders and provide technical contributions to relevant security projects.
  • Maintain awareness of emerging SIEM, logging, and cybersecurity technologies.
  • Install, configure, monitor, troubleshoot, and maintain security-system components.
  • Ensure interoperability with dependent systems, applications, and external tools.
  • Analyze system, security, and application logs to diagnose faults and identify abnormal behaviour.
  • Monitor service performance and ensure compliance with SLAs and defined KPIs.
  • Provide occasional on-call support to maintain SIEM infrastructure availability.
  • Support the full service lifecycle according to ITIL practices, including:
    • Service design and transition
    • Operations and support
    • Change management
    • Continual service improvement
  • Identify and propose improvements that increase system currency, stability, and reliability.
  • Prepare business justifications, technical documentation, and implementation plans for the Change Management Board.
  • Implement approved changes in coordination with relevant stakeholders.
  • Coordinate with service delivery managers, users, NATO entities, and industry partners.
  • Develop and maintain operating procedures, technical guidelines, service designs, and system documentation.
  • Produce technical and executive reports, presentations, and briefings for audiences up to NATO executive level.

Mandatory experience and knowledge

  • At least one year of substantial hands-on experience administering Splunk in a large enterprise, including deployment, installation, configuration, and maintenance.
  • Hands-on experience designing and maintaining distributed Splunk architectures.
  • At least two years of expert-level experience in SIEM and log-collection management.
  • Demonstrated ability to analyze logs for faults and abnormal behaviour.
  • Strong Linux system and application administration and troubleshooting experience.
  • Practical systems and tools administration experience.
  • Comprehensive understanding of:
    • Computer and communications security
    • Networking
    • Modern operating-system and application vulnerabilities
  • Automation experience using Bash, Python, or Ansible.
  • Solid understanding of regular expressions.
  • Ability to write clear technical documentation and procedures.
  • Strong written and verbal communication skills, including explaining complex issues to varied audiences.

Desirable technical experience

  • Splunk Enterprise Security, Splunk SOAR, and Splunk UBA administration.
  • Developing Splunk applications.
  • Managing Splunk content, particularly Enterprise Security and Advanced Search and Reporting.
  • Creating or modifying custom log parsers.
  • Git and Ansible.
  • Python, shell scripting, or PowerShell.
  • Automating system integrations through APIs.
  • Cloud-based log collection in Azure or AWS.
  • Network infrastructure and virtualized environments.
  • Cybersecurity work in a CERT, security office, or similar organization.
  • Experience in regulated or highly controlled environments such as defence, government, finance, or large enterprises.
  • Strong understanding of the confidentiality, integrity, and availability—or CIA—security principles.
  • ITIL Service Management certification or experience.

Education

The document contains two slightly different education statements:

  • The general requirement states a related bachelor’s degree plus two years of relevant post-degree experience, or at least five years of extensive and progressive relevant experience without a degree.
  • A later education section states a related bachelor’s degree plus three years of relevant post-degree experience.

A bachelor’s degree in cybersecurity, information technology, computer science, or a related field is preferred.

Certifications

Industry-recognized cybersecurity certifications are requested, such as:

  • CISSP
  • CISM
  • CISA
  • GSNA
  • SANS GIAC certifications

ITIL Service Management certification is also desirable.

Language and professional skills

  • English at NATO STANAG 6001 Level 3, “Professional Proficiency,” or higher.
  • Very good analytical and communication skills.
  • Ability to collaborate with technical teams, operational managers, customers, executives, and external partners.
  • Military or governmental organization experience is desirable.

Working conditions

  • Normal office environment, with standard hours of approximately 08:30–17:30.
  • The role may require:
    • On-call work after hours, on weekends, and on holidays.
    • Twelve-hour weekday shifts, while maintaining an average of no more than 38 hours per week.
    • Extended hours, night shifts, and weekend work during enterprise-level cyber incidents to support a 24/7 response.
  • NCIA will provide equipment for processing restricted information.
  • If remote work is authorized, the contractor must provide suitable equipment for public and unclassified information and be able to participate in Microsoft-based video meetings.

Travel

  • Travel to other NCIA locations may be required for operational duties.
  • Authorized travel expenses will be reimbursed under NATO regulations.
  • Travel requests must originate from the contractor’s designated duty station.
       

Reageren op aanvraag

Terug