Siem Engineer

Il y a 21 heures

Luxembourg Relatech Temps plein
🚀 The Opportunity To strengthen our Advisory Business Unit, we are looking for a hands-on SIEM Engineer with a strong focus on Log Management, Data Quality, parsing and troubleshooting. The role will ensure that collected logs are complete, correctly parsed, normalized, traceable, and suitable for security monitoring, detection engineering and investigation. 🧠

What You'll Do
In this role, you will have the opportunity to:
• Monitor existing log sources and ensure continuous and reliable data collection.
• Onboard new log sources according to the Log Management roadmap.
• Perform quantitative and qualitative Log Quality Assurance.
• Identify and troubleshoot logging gaps, parsing defects and normalization issues.
• Manipulate, transform, filter, route and normalize event data across SIEM pipelines.
• Maintain log-source inventories, parsing specifications, mappings, test evidence and technical documentation.
• Prepare and validate production-ready changes.
• Provide operational backup and first-line troubleshooting for the Splunk infrastructure.
• Support Splunk use cases through testing, validation and tuning. 👤 Who We're Looking For Skills & Qualifications
• Bachelor's degree in Computer Science, Information Security or a related field, or equivalent professional experience.
• Professional proficiency in English.
• Knowledge of French or Italian is considered an advantage.
• Availability to work on-site in Luxembourg
• Solid IT fundamentals across systems, networking, authentication and logging.
• Excellent Regular Expression (RegEx) skills.
• Strong log parsing and data normalization capabilities, particularly with semi-structured logs.
• Basic scripting/automation skills in at least one language such as Python, PowerShell or Bash.
• Strong analytical skills, accuracy and attention to detail.
• Ability to troubleshoot logging issues collaboratively with technical teams and Log Source Owners.
• Good documentation and communication skills.

Experience:
at least 3 years of relevant experience Nice to Have:
• Working knowledge of Splunk and SPL, including knowledge objects and search-time troubleshooting.
• Exposure to Splunk architecture and administration concepts, including Search Heads, Indexers and Forwarders.
• Familiarity with SIEM engineering monitoring use cases, such as log loss and latency detection.
• Splunk certifications are considered a plus. We're looking for someone who is: ✔ Curious ✔ Proactive ✔ Collaborative ✔ Eager to learn and grow 🌱 What You'll Find at Relatech
• Meaningful, high-impact projects
• A collaborative and multidisciplinary environment
• Clear professional growth opportunities
• Continuous learning and on-the-job training
• Innovative technologies and methodologies
• Flexibility and attention to work-life balance
• Inclusion & Equal Opportunities: We believe innovation and diversity go hand in hand. That's why we foster an inclusive, open, and respectful workplace. Every application is evaluated based on skills, potential, and motivation, regardless of gender, age, ethnicity, disability, sexual orientation, religion, or any other protected characteristic.

Location:
Luxembourg Work model: On-site Contract: CDI Contract 🔗 Learn More

About Us
Discover more about our world at 🌐 www.relatech.com