Skip to content

Open nowPosted 6 hours ago

C005335 Splunk Engineer (NS) - THU 22 Oct

Workable (global search)107,778 open roles

Where
Mons, Wallonia, Belgium
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowC005335 Splunk Engineer (NS) - THU 22 OctWorkable (global search) · Mons, Wallonia, Belgium
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 3 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted 6 hours ago

Workable (global search) median: 3 days open

The posting

Previously submitted bids have been found non-compliant for the following reasons:

The application does not demonstrate “At least 2 years and expert level experience related to SIEM and Log collection management activities.”

The application does not demonstrate “At least 1 year of extensive practical experience as SIEM administrator with Splunk in large enterprise environment (deployment, installation, configuration and maintenance).”

The candidate was not able to demonstrate the expected level of proficiency with Linux during the interview

"Missing: “At least 1 year of extensive practical experience as SIEM administrator with Splunk in large enterprise environment"" Missing ""Possess industry leading certification in the area of Cyber ..."""

Deadline Date: Thursday 22 October 2026

Requirement: Splunk Engineer

Location: Mons, BE

Full Time On-Site: Yes

Time On-Site: 100%

Total Scope of the request (hours): 140

Required Start Date: 1 December 2026

End Contract Date: 31 December 2026

Required Security Clearance: NATO SECRET

Duties & Role:

Under the direction of Cyber Security Data Engineering Cell Head (CSDE), or a delegated authority, the incumbent will perform duties such as the following:

  • Act as one of the main engineers and Subject Matter Expert (SME) for SIEM and Log collection services within the Cyber Security Data team.
  • As the SME, you will provide advice and technical assistance to other stakeholders, maintain technical expertise, awareness, and developments in related new technologies, and provide technical contributions to any projects related to the data security systems.
  • Be responsible for management and further development of the data security systems;
  • The contractor may occasionally be required to provide on-call support and intervene in the event of an issue to ensure the continued operational availability of the SIEM monitoring infrastructure
  • Following ITIL standards, provide support to Operations and Service Delivery management covering all stages of the data security systems lifecycle (e.g. Service Design, Transition, Operations, Change Management and Continual Service Improvement).
  • Ensure that data security systems are installed, configured, and operating correctly and in line with dependencies with others systems or applications required.
  • Ensure that all system components are continuously monitored and take appropriate technical and non-technical actions for solving detected issues.
  • Ensure that data security systems operate within any KPI's, as defined in Service Level Agreements with NCSC customers.
  • Support integration with external tools and any associated activities.
  • Proactively identify and propose system improvements to ensure an up-to-date and stable environment.
  • Justify business needs, prepare documentation and implementation plan for the Change Management Board. Implement the approved changes following co-ordination with other stakeholders.
  • Coordinate with service delivery managers, end users and other stakeholders in support of related services; communicate with other NATO entities as well as industry partners where required;
  • Develop and maintain documentation guidelines, standard operating procedures, system and service design documents and other relevant documentation that support management of the data security systems.
  • Create technical and/or executive level reports as required; organise and deliver presentations and briefings for various audience up to NATO executive level.
  • Perform other duties as may be required.

Specific Working Conditions: Normal working hours 0830-1730. On-call duties after working hours, on weekends or holidays are required.

If working from a remote location, the contractor shall provide IT equipment for the processing of public and unclassified information in support of their duties, including the capability to participate in video meetings using Microsoft based collaboration tools.

The incumbent may require to work on 12 hours pattern during weekdays but not exceeding an average of 38h per week In case of an enterprise-level Cyber Incident, the incumbent may be required to work extended hours and on shifts, including nights and weekends, to provide a 24/7 Cyber Incident Response.

Travel required: The contractor may be required to travel to NCIA locations in support of operational duties. In such cases the contractor will be reimbursed for travel costs according to NATO regulations for traveling on NATO duty. Contractors traveling for work purposes shall initiate travel requests from their designated duty station only

Requirements

Skills, Knowledge & Experience:

  • The candidate must have a currently active NATO SECRET security clearance
  • A minimum requirement of a Bachelor's degree from a nationally recognised/certified university in a related discipline and two years post‑related experience. Alternatively, the lack of a university degree may be compensated by the demonstration of a candidate's particular abilities or experience of interest to the NCI Agency, provided the candidate has at least five years of extensive and progressive expertise in duties related to the function of the post.
  • At least 1 year of extensive practical experience as SIEM administrator with Splunk in large enterprise environment (deployment, installation, configuration and maintenance).
  • Hands-on experience in the design and maintenance of distributed Splunk architectures.
  • At least 2 years and expert level experience related to SIEM and Log collection management activities.
  • Demonstrable experience of analysing and interpreting system, security and application logs in order to diagnose faults and spot abnormal behaviours.
  • Practical hands-on experience in systems and tools administration, especially Linux environment;
  • Comprehensive knowledge of the principles of computer and communication security, networking, and the vulnerabilities of modern operating systems and applications.
  • Practical skills in writing Bash, Python or Ansible scripts to support repetitive tasks automation;
  • Solid Linux system and application administration and troubleshooting skills.
  • Solid understanding of regular expressions.
  • Ability to develop clear and concise technical documentation, including procedures.
  • Good communication abilities, both written and verbal, with the ability to clearly and successfully articulate complex issues to a variety of audiences and teams.
  • Very good communication and analytical skills.
  • Language proficiency in English: meet or exceed the NATO STANAG 6001 Level 3 "Professional Proficiency".
  • Possessing industry leading certification in the area of Cyber Security such as CISSP, CISM, CISA, GSNA, and SANS GIAC.

Education, Experience and Training (Desirable):

  • A university degree (Bachelor's) in Cyber Security, Information Technology, Computer Science or a related discipline.
  • Experience working in a regulated, high control environment such as defence, government, financial services or other enterprise sectors.
  • Extensive practical experience (as system administrator) with Splunk Enterprise security, Splunk SOAR and Splunk UBA.
  • Practical experience with Git software.
  • Hands-on experience with Ansible as an automation technology.
  • Experience in creation/modification of custom parsers.
  • Software engineering including programming and/or scripting knowledge (python, shell scripting, PowerShell).
  • Prior experience automating interactions between systems using APIs.
  • A solid understanding of Information Security Practices; relating to the Confidentiality, Integrity and Availability of information (CIA triad.).
  • ITIL Service Management certifications.
  • Experience in developing Splunk Applications.
  • Content management experience in Splunk, especially Enterprise Security and Advanced Search and Reporting.
  • Hands-on experience with network infrastructure and virtualized environments.
  • Previous experience working for Cyber Security related organisations (CERTs, security offices).
  • Experience with log collection in cloud environment such as Azure or AWS
  • Experience in working for or supporting a military or governmental organization.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.