KEY RESPONSIBILITIES • Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure. • Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments. • Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment. • Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures. • Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing. • Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility. • Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records. • Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution. • Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers. |
REQUIRED EXPERIENCE & SKILLS • Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering. • Hands-on expertise with an enterprise SIEM, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps are also relevant. • Experience with log onboarding and troubleshooting across Windows, Linux, Microsoft Entra ID, cloud, network, endpoint, and application environments. • Proficiency in KQL, SPL, SQL, or a comparable query language, including analytics and performance troubleshooting. • Knowledge of syslog, APIs, agents, collectors, event streaming, common schemas, parsing, normalization, and enrichment. • Scripting or automation experience using PowerShell, Python, REST APIs, Git, CI/CD, or infrastructure-as-code. • Understanding of detection engineering, incident response, digital forensics, networking, security controls, and data protection. • Strong analytical, documentation, stakeholder communication, and end-to-end ownership skills; professional English required. PREFERRED QUALIFICATIONS • SIEM and security data lake architecture; SOAR and detection-as-code practices. • Experience in regulated, critical-infrastructure, energy, or OT environments. • Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements. • Relevant Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certification. |