SIEM Administrator / Engineer
ВакансіїSummary
Andersen is hiring a SIEM Administrator / Engineer for a project enhancing a SIEM platform and supporting centralized security monitoring and threat detection.
Our customer is a technology and consulting organization providing digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support. It helps organizations modernize complex technology environments, strengthen security, and improve the reliability and scalability of their digital operations. By combining technical expertise with modern technologies and service-oriented delivery, the company supports digital transformation, operational efficiency, and the continuous improvement of critical IT systems across multiple markets.
The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment. It includes managing and enhancing the SIEM platform to support centralized security monitoring, threat detection, and reliable cyber defense operations across multiple organizations worldwide.
Responsibilities
- Administering, maintaining and upgrading the SIEM platform, including health, performance, capacity and licensing.
- Onboarding and normalizing new log sources (network, endpoint, cloud, identity, applications), including in multi-tenant setups.
- Developing, tuning and maintaining detection rules, correlation searches, dashboards and reports.
- Reducing false positives together with SOC analysts and implementing new use cases.
- Building and maintaining SOAR playbooks and integrations.
- Maintaining documentation, data retention policies and access control.
- Supporting audits and compliance reporting.
Requirements
- Experience in IT or cybersecurity for 5+ years, including 3+ years administering an enterprise SIEM in production.
- Deep hands-on experience with at least one major SIEM: Microsoft Sentinel, Splunk ES, IBM QRadar or Elastic Security.
- Hands-on experience with log source onboarding, parsing, and normalization using Syslog, CEF, Windows Event Forwarding (WEF), and API-based cloud connectors.
- Experience writing detection content in the platform's query language (KQL, SPL, AQL or equivalent).
- Understanding of MITRE ATT&CK for mapping detection coverage.
- Clean professional records and willingness to undergo background verification.
- Level of English – from Upper-Intermediate and above.
Desired skills
- Vendor certifications (e.g. Microsoft SC-200, Splunk Certified Admin/Architect, IBM QRadar).
- SOAR experience (Sentinel Logic Apps, Splunk SOAR, Cortex XSOAR).
- Multi-tenant SIEM or MSSP experience.
- Experience in scripting and automation (Python, PowerShell) and Infrastructure as Code.
- Experience working with detection-as-code practices (Sigma, Git-based rule management).
Reasons to join us
- Andersen cooperates with such companies as Siemens, Johnson & Johnson, AstraZeneca, BNP Paribas, Allianz, Ryanair, TUI, Verivox, Media Markt, etc..
- For the past four years, our company has been growing annually by 60–100%, and we constantly involve top-notch specialists in our team.
- Andersen has mentoring and adaptation systems for new employees, and transparent performance review and assessment systems will allow you to determine your development path and plan your growth.
- The most important thing that we value in our employees is a commitment to continuous learning. The company supports them in this and gives them access to the best educational platforms, seminars, and practices. In addition, for over 19 years, Andersen has assembled a huge knowledge base and established a robust resource management institution.
- We have been strengthening our expertise since 2007. During this time, we have formed excellent teams with streamlined processes, where you can learn something new from your colleagues every day and enjoy your work.
- We are a cool young team of like-minded people communicating informally.
- You'll have a stable and competitive salary and an extensive benefits package.
- At Andersen, we have many different ways to grow. You can improve as a specialist or a manager, and all your activities will be decently rewarded.
Join us!
Локації
Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Hungary, Italy, Latvia, Lithuania, Luxembourg, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, The Netherlands
Будемо раді бачити вас!
Ми обробляємо персональні дані відповідно до GDPR
Шукаєте нові можливості для розвитку? Ознайомтеся з відкритими позиціями в Andersen просто зараз