SIEM Administrator / Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Hungary, Italy, Latvia, Lithuania, Luxembourg, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, or The Netherlands
Salary: EUR 3,500–6,200 gross per month. Final compensation depends on experience, location, and professional growth.
Company
provides digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support for organizations modernizing complex technology environments.
What you will do
- Administer, maintain, upgrade, and monitor the health, performance, capacity, and licensing of an enterprise SIEM platform.
- Onboard and normalize network, endpoint, cloud, identity, and application log sources in multi-tenant environments.
- Develop, tune, and maintain detection rules, correlation searches, dashboards, and reports.
- Work with SOC analysts to reduce false positives and implement new detection use cases.
- Build and maintain SOAR playbooks and integrations.
- Maintain documentation, data retention policies, access controls, audit support, and compliance reporting.
Requirements
- 5+ years of experience in IT or cybersecurity, including 3+ years administering an enterprise SIEM in production.
- Hands-on experience with at least one major SIEM platform: Microsoft Sentinel, Splunk ES, IBM QRadar, or Elastic Security.
- Experience onboarding, parsing, and normalizing logs using Syslog, CEF, Windows Event Forwarding, and API-based cloud connectors.
- Experience writing detection content in KQL, SPL, AQL, or an equivalent query language.
- Understanding of MITRE ATT&CK and detection coverage mapping.
- Upper-Intermediate English or higher, a clean professional record, and willingness to undergo background verification are required.
Nice to have
- Vendor certifications such as Microsoft SC-200, Splunk Certified Admin or Architect, or IBM QRadar certifications.
- SOAR experience with Sentinel Logic Apps, Splunk SOAR, or Cortex XSOAR.
- Multi-tenant SIEM or MSSP experience.
- Scripting and automation experience with Python or PowerShell, Infrastructure as Code, and detection-as-code practices using Sigma or Git-based rule management.
Culture & Benefits
- Stable salary and an extensive benefits package.
- Mentoring, onboarding, transparent performance reviews, and structured career development.
- Access to educational platforms, seminars, internal expertise, and a large knowledge base.
- Opportunities to grow as either a technical specialist or manager.
- Work with international clients across complex cybersecurity and digital-services projects.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →