FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in SIEM integration, particularly with Sekoia.io and Splunk, alongside strong capabilities in log collection, parsing, and security event management. Proficient in scripting and automation, with a solid understanding of cybersecurity principles and compliance.
Highest-signal resume keywords
SIEM IntegrationSekoia.ioSplunk / Splunk ESLog Collection and ParsingOperational Cybersecurity
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Log Collection ArchitecturesLog Parsing ConfigurationsRegular ExpressionsScripting: Python, Bash, PowerShell, AnsibleSecurity Event NormalizationECS/CIM MappingsIncident Response PrinciplesDetection and InvestigationMulti-Client SIEM IntegrationNetwork Protocols
Soft Skills
Strong Writing SkillsCustomer-FocusedMeticulousSelf-DirectedTeam Player
Tools & Technologies
AnsibleGitEDR: HarfangLab, SentinelOne, CrowdStrike Falcon, Microsoft Defender for EndpointSIEM Platforms: LogPoint, Microsoft Sentinel, ElasticNessusRapid7QualysCisco UmbrellaVade Secure
Industry Keywords
Operational CybersecurityLogging ComplianceMITRE ATT&CK FrameworkCloud ArchitecturesIDS/IPSWAFsXDRSOAR
Tech Stack
Tools & technologiesAnsibleCloudDNSFluxLinuxPythonSplunk
About the role
Key responsibilities & impact- Design log collection pipelines and architectures with clients
- Size, secure, and document collection infrastructures
- Lead client-side prerequisites and challenge proposed architectures
- Implement collection from heterogeneous on-premises and SaaS/Cloud sources
- Handle non-standard collection methods using flat files, REST APIs, webhooks, message queues, and proprietary formats
- Write and maintain log parsing configurations, including field extraction, normalization, timestamping, multiline handling, and regular expressions
- Create or enhance Sekoia.io intakes and Splunk Technical Add-ons
- Develop, adapt, and troubleshoot Splunk configurations, ensuring version control, testing, and documentation
- Verify the completeness, quality, volume, and freshness of received events
- Check source-side logging compliance and provide client recommendations
- Validate ECS/CIM mappings with detection teams
- Diagnose end-to-end collection failures and identify root causes
- Implement collection monitoring and sustainable corrective actions
- Contribute to the operational and security maintenance of SIEM infrastructures
- Evolve architectures and develop Ansible playbooks
- Support project managers with architecture design and technical security requirements
- Contribute to security solution configuration, change management, and production installation validation
- Manage access rights, handle incidents and anomalies, and document processes
- Participate in client steering committees
- Provide occasional support to the SOC by analyzing and qualifying alerts, conducting initial investigations, and improving detection scenarios
Requirements
What you’ll need- Proven, significant experience as a SIEM integrator with Sekoia.io and Splunk / Splunk ES
- Bachelor’s to Master’s degree in computer science or cybersecurity
- 3 to 6 years of experience in operational cybersecurity
- At least 2 years focused on integrating log sources into a SIEM in a multi-client or multi-environment context
- Additional SOC experience (detection, alert qualification, incident response) is a plus
- Strong foundations in Linux and Windows systems and networking, including protocols, traffic flows, TLS, DNS, routing, and filtering
- Proficiency in security event collection, normalization, correlation, and enrichment mechanisms
- Knowledge of logging formats and protocols: syslog (RFC 3164/5424), CEF, LEEF, JSON, XML, CSV, Windows Event Log, and REST APIs
- Comfortable with regular expressions and reading raw logs
- Scripting and automation skills: Python, Bash, PowerShell, Ansible; experience using Git
- Understanding of detection, investigation, and incident response principles, as well as the MITRE ATT&CK framework
- Hands-on experience with an EDR is a plus: HarfangLab, SentinelOne, CrowdStrike Falcon, or Microsoft Defender for Endpoint
- Knowledge of other SIEM platforms is a plus: LogPoint, Microsoft Sentinel, or Elastic
- Knowledge of Snort or Suricata is a plus
- Knowledge of Nessus, Rapid7, or Qualys is a plus
- Knowledge of Cisco Umbrella or Vade Secure is a plus
- Familiarity with firewalls, WAFs, IDS/IPS, XDR, SOAR, and Cloud architectures
- Strong writing skills and technical English proficiency
- Meticulous, self-directed, customer-focused, and a strong team player
Benefits
Comp & perks- Hybrid / partial remote work
- Permanent employment contract
- Training and skills development opportunities through occasional assignments within the SOC team
- Work with a wide range of SIEM/SOC technologies and platforms
- Participation in diverse client projects and environments
