Sii
1 month ago
Senior SIEM Engineer m f d
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- Sii
- Location
- Polska, lubelskie, Lublin Poland
- Posted
- 1 month ago
Job description
We are looking for an experienced SIEM Engineer to join a project in the energy sector. In this role, you will be responsible for the design, administration, and improvement of SIEM platforms supporting threat detection, incident handling, and regulatory compliance. A key area will be the building and optimization of processes for acquiring, processing, and analyzing data from an extensive, global IT environment. Your tasks: * Designing, configuring, maintaining, and monitoring the SIEM platform and related infrastructure. * Collecting and onboarding security logs from various sources such as identities, endpoints, networks, cloud, and business applications. * Creating reliable data pipelines and developing processes for parsing, normalizing, transforming, and enriching data contextually. * Monitoring telemetry status and troubleshooting issues related to missing sources, collection delays, volume anomalies, and connector failures. * Supporting detection engineering by providing required fields, correlation logic, threat intelligence, and testing. * Optimizing ingestion, storage, retention, query performance, and cost processes without reducing required security visibility. * Maintaining architecture diagrams, log source inventories, onboarding standards, runbooks, and configuration records. * Supporting SOC investigations, threat hunting, incident response, and audits. Requirements: * Minimum 3 years of experience in SIEM engineering, security monitoring, or log management. * Hands-on experience with SIEM platforms, preferably Microsoft Sentinel, but also Splunk, QRadar, Elastic, or Google SecOps. * Experience in log onboarding and troubleshooting in Windows, Linux, cloud, network, endpoint, and application environments. * Proficiency in KQL, SPL, SQL, or similar query languages. * Familiarity with syslog, APIs, agents, collectors, event streaming, and parsing/enrichment processes. * Previous experience in scripting or automation using PowerShell, Python, REST API, Git, CI/CD, or infrastructure-as-code. * Understanding of detection engineering, incident response, digital forensics, and network security. * English language proficiency at a minimum of B2 level. Nice to have: * Experience in regulated critical infrastructure environments, energy, or OT. * Familiarity with NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements. * Microsoft, Splunk, GIAC, CISSP, CISM certifications, or equivalent.
Required skills
- ci/cd
- incident response
- sql
- python
- git
- rest api
- powershell
- elastic
- api
- cloud security
- cissp
- siem
- splunk
- threat detection
- ot
- nis2
- cism
- endpoint security
- security monitoring
- network security
- infrastructure-as-code
- iso/iec 27001
- microsoft certification
- qradar
- digital forensics
- kql
- security information and event management
- syslog
- microsoft sentinel
- log management
- giac
- detection engineering
- spl
- google secops
- iec 624443
- splunk certification
Interested in this position?
Create your free account and tailor your CV to match this job.