Login Enter

Sii

1 month ago

Senior SIEM Engineer m f d

Sign up free Log in

Sign up to save this job, get alerts, and apply with an optimized CV.

Company information

Company
Sii
Location
Polska, lubelskie, Lublin Poland
Posted
1 month ago
View all jobs at Sii

Job description

We are looking for an experienced SIEM Engineer to join a project in the energy sector. In this role, you will be responsible for the design, administration, and improvement of SIEM platforms supporting threat detection, incident handling, and regulatory compliance. A key area will be the building and optimization of processes for acquiring, processing, and analyzing data from an extensive, global IT environment. Your tasks: * Designing, configuring, maintaining, and monitoring the SIEM platform and related infrastructure. * Collecting and onboarding security logs from various sources such as identities, endpoints, networks, cloud, and business applications. * Creating reliable data pipelines and developing processes for parsing, normalizing, transforming, and enriching data contextually. * Monitoring telemetry status and troubleshooting issues related to missing sources, collection delays, volume anomalies, and connector failures. * Supporting detection engineering by providing required fields, correlation logic, threat intelligence, and testing. * Optimizing ingestion, storage, retention, query performance, and cost processes without reducing required security visibility. * Maintaining architecture diagrams, log source inventories, onboarding standards, runbooks, and configuration records. * Supporting SOC investigations, threat hunting, incident response, and audits. Requirements: * Minimum 3 years of experience in SIEM engineering, security monitoring, or log management. * Hands-on experience with SIEM platforms, preferably Microsoft Sentinel, but also Splunk, QRadar, Elastic, or Google SecOps. * Experience in log onboarding and troubleshooting in Windows, Linux, cloud, network, endpoint, and application environments. * Proficiency in KQL, SPL, SQL, or similar query languages. * Familiarity with syslog, APIs, agents, collectors, event streaming, and parsing/enrichment processes. * Previous experience in scripting or automation using PowerShell, Python, REST API, Git, CI/CD, or infrastructure-as-code. * Understanding of detection engineering, incident response, digital forensics, and network security. * English language proficiency at a minimum of B2 level. Nice to have: * Experience in regulated critical infrastructure environments, energy, or OT. * Familiarity with NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements. * Microsoft, Splunk, GIAC, CISSP, CISM certifications, or equivalent.

Required skills

Interested in this position?

Create your free account and tailor your CV to match this job.