Looking for something else?
Find a vacancy that works for you. Send us your CV to receive a personalized offer.
Find me a jobWe are looking for a SIEM Engineer to design, operate, and continuously improve enterprise security logging and monitoring capabilities. The role ensures reliable, high-quality telemetry for threat detection, incident response, digital forensics, and compliance, while optimizing platform performance, scalability, and cost.
The role follows a hybrid working model, with three days per week based in the office (Tuesday, Wednesday, Thursday).
Responsibilities
- Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure
- Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments
- Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment
- Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures
- Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing
- Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility
- Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records
- Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution
- Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers
Requirements
- Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering
- Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps are also relevant
- Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments
- Proficiency in KQL/SPL/SQL, or a comparable query language, including analytics and performance troubleshooting
- Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment
- Scripting or automation experience using PowerShell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code
- Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection
- Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required
Nice to have
- SIEM and security data lake architecture; SOAR and detection-as-code practices
- Experience in regulated, critical-infrastructure, energy, or OT environments
- Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements
- Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certification
