Splunk Engineer
Role: Splunk Engineer
Location: Mons, Belgium
Working arrangement: Full-time on-site
Security clearance: NATO Secret
Primary duties
- Serve as a principal engineer and Subject Matter Expert for SIEM and log-collection services.
- Manage, maintain, and further develop Splunk and related data-security systems.
- Advise stakeholders and provide technical contributions to relevant security projects.
- Maintain awareness of emerging SIEM, logging, and cybersecurity technologies.
- Install, configure, monitor, troubleshoot, and maintain security-system components.
- Ensure interoperability with dependent systems, applications, and external tools.
- Analyze system, security, and application logs to diagnose faults and identify abnormal behaviour.
- Monitor service performance and ensure compliance with SLAs and defined KPIs.
- Provide occasional on-call support to maintain SIEM infrastructure availability.
- Support the full service lifecycle according to ITIL practices, including:
- Service design and transition
- Operations and support
- Change management
- Continual service improvement
- Identify and propose improvements that increase system currency, stability, and reliability.
- Prepare business justifications, technical documentation, and implementation plans for the Change Management Board.
- Implement approved changes in coordination with relevant stakeholders.
- Coordinate with service delivery managers, users, NATO entities, and industry partners.
- Develop and maintain operating procedures, technical guidelines, service designs, and system documentation.
- Produce technical and executive reports, presentations, and briefings for audiences up to NATO executive level.
Mandatory experience and knowledge
- At least one year of substantial hands-on experience administering Splunk in a large enterprise, including deployment, installation, configuration, and maintenance.
- Hands-on experience designing and maintaining distributed Splunk architectures.
- At least two years of expert-level experience in SIEM and log-collection management.
- Demonstrated ability to analyze logs for faults and abnormal behaviour.
- Strong Linux system and application administration and troubleshooting experience.
- Practical systems and tools administration experience.
- Comprehensive understanding of:
- Computer and communications security
- Networking
- Modern operating-system and application vulnerabilities
- Automation experience using Bash, Python, or Ansible.
- Solid understanding of regular expressions.
- Ability to write clear technical documentation and procedures.
- Strong written and verbal communication skills, including explaining complex issues to varied audiences.
Desirable technical experience
- Splunk Enterprise Security, Splunk SOAR, and Splunk UBA administration.
- Developing Splunk applications.
- Managing Splunk content, particularly Enterprise Security and Advanced Search and Reporting.
- Creating or modifying custom log parsers.
- Git and Ansible.
- Python, shell scripting, or PowerShell.
- Automating system integrations through APIs.
- Cloud-based log collection in Azure or AWS.
- Network infrastructure and virtualized environments.
- Cybersecurity work in a CERT, security office, or similar organization.
- Experience in regulated or highly controlled environments such as defence, government, finance, or large enterprises.
- Strong understanding of the confidentiality, integrity, and availability—or CIA—security principles.
- ITIL Service Management certification or experience.
Education
The document contains two slightly different education statements:
- The general requirement states a related bachelor’s degree plus two years of relevant post-degree experience, or at least five years of extensive and progressive relevant experience without a degree.
- A later education section states a related bachelor’s degree plus three years of relevant post-degree experience.
A bachelor’s degree in cybersecurity, information technology, computer science, or a related field is preferred.
Certifications
Industry-recognized cybersecurity certifications are requested, such as:
- CISSP
- CISM
- CISA
- GSNA
- SANS GIAC certifications
ITIL Service Management certification is also desirable.
Language and professional skills
- English at NATO STANAG 6001 Level 3, “Professional Proficiency,” or higher.
- Very good analytical and communication skills.
- Ability to collaborate with technical teams, operational managers, customers, executives, and external partners.
- Military or governmental organization experience is desirable.
Working conditions
- Normal office environment, with standard hours of approximately 08:30–17:30.
- The role may require:
- On-call work after hours, on weekends, and on holidays.
- Twelve-hour weekday shifts, while maintaining an average of no more than 38 hours per week.
- Extended hours, night shifts, and weekend work during enterprise-level cyber incidents to support a 24/7 response.
- NCIA will provide equipment for processing restricted information.
- If remote work is authorized, the contractor must provide suitable equipment for public and unclassified information and be able to participate in Microsoft-based video meetings.
Travel
- Travel to other NCIA locations may be required for operational duties.
- Authorized travel expenses will be reimbursed under NATO regulations.
- Travel requests must originate from the contractor’s designated duty station.