Sii Poland

SII UKRAINE

SII SWEDEN

  • Trainings
  • Career
Join us Contact us
Back

Sii Poland

SII UKRAINE

SII SWEDEN

Back

Senior SIEM Engineer (f/m/x)

  • Regular, 
  • Senior
  • Remote, 
  • Hybrid, 
  • Office
  • Multiple locations Show all
This translation is generic and may include errors. Show original text
This offer base language is Polish. Translate into English.

Technologies & tools

We are looking for an experienced SIEM Engineer to join a project in the energy sector. In this role, you will be responsible for designing, administering, and improving SIEM platforms that support threat detection, incident handling, and regulatory compliance. A key focus will be building and optimizing data ingestion, processing, and analysis workflows within a complex, global IT environment.

Your tasks

  • Designing, configuring, maintaining, and monitoring the SIEM platform and related infrastructure
  • Collecting and onboarding security logs from various sources such as identities, endpoints, networks, cloud, and business applications
  • Creating reliable data pipelines and developing parsing, normalization, transformation, and contextual enrichment processes
  • Monitoring telemetry health and troubleshooting missing sources, ingestion delays, volume anomalies, and connector failures
  • Supporting detection engineering by providing required fields, correlation logic, threat intelligence, and testing
  • Optimizing ingestion, storage, retention, query performance, and costs without reducing required security visibility
  • Maintaining architecture diagrams, log source inventory, onboarding standards, runbooks, and configuration records
  • Supporting SOC investigations, threat hunting, incident response, and audits

Requirements

  • Minimum 3 years of experience in SIEM engineering, security monitoring, or log management
  • Hands-on experience with SIEM platforms, preferably Microsoft Sentinel, but also Splunk, QRadar, Elastic, or Google SecOps
  • Experience onboarding logs and troubleshooting in Windows, Linux, cloud, network, endpoint, and application environments
  • Proficiency in KQL, SPL, SQL, or similar query languages
  • Knowledge of syslog, APIs, agents, collectors, event streaming, and parsing and enrichment processes
  • Previous work in scripting or automation using PowerShell, Python, REST API, Git, CI/CD, or infrastructure-as-code
  • Understanding of detection engineering, incident response, digital forensics, and network security
  • English language proficiency at a minimum B2 level

Nice to have

  • Experience in regulated critical infrastructure, energy, or OT environments
  • Knowledge of NIS2, ISO/IEC 27001, IEC 62443, and security log retention requirements
  • Microsoft, Splunk, GIAC, CISSP, CISM, or equivalent certifications

Job no. JOB-E4BP6

Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.

Technologie i narzędzia

Szukamy doświadczonego SIEM Inżyniera , który dołączy do projektu realizowanego w sektorze energetycznym. W tej roli będziesz odpowiadać za projektowanie, administrację i doskonalenie platform SIEM wspierających wykrywanie zagrożeń, obsługę incydentów oraz realizację wymagań regulacyjnych. Kluczowym obszarem będzie budowa i optymalizacja procesów pozyskiwania, przetwarzania oraz analizy danych z rozbudowanego, globalnego środowiska IT.

Twoje zadania

  • Projektowanie, konfigurowanie, utrzymywanie i monitorowanie platformy SIEM oraz związanej infrastruktury
  • Zbieranie i onboardowanie logów związanych z bezpieczeństwem z różnych źródeł, takich jak tożsamości, punkty końcowe, sieci, chmura i aplikacje biznesowe
  • Tworzenie niezawodnych potoków danych oraz rozwijanie procesów parsowania, normalizacji, transformacji i wzbogacania kontekstowego
  • Monitorowanie stanu telemetrii oraz rozwiązywanie problemów związanych z brakującymi źródłami, opóźnieniami w pobieraniu, anomaliami wolumenu i awariami konektorów
  • Wsparcie inżynierii detekcji poprzez dostarczanie wymaganych pól, logiki korelacji, informacji o zagrożeniach oraz testowanie
  • Optymalizacja procesów pobierania, przechowywania, retencji, wydajności zapytań oraz kosztów, nie zmniejszając wymaganej widoczności bezpieczeństwa
  • Utrzymywanie diagramów architektury, inwentarza źródeł logów, standardów onboardingu, runbooków oraz zapisów konfiguracyjnych
  • Wsparcie dochodzeń SOC, poszukiwania zagrożeń, reakcji na incydenty oraz audytów

Wymagania

  • Minimum 3 lata doświadczenia w inżynierii SIEM, monitorowaniu bezpieczeństwa lub zarządzaniu logami
  • Praktyczne doświadczenie z platformami SIEM, preferowane Microsoft Sentinel, ale również Splunk, QRadar, Elastic lub Google SecOps
  • Doświadczenie w onboardowaniu logów oraz rozwiązywaniu problemów w środowiskach Windows, Linux, chmura, sieci, punkty końcowe oraz aplikacje
  • Biegłość w KQL, SPL, SQL lub podobnych językach zapytań
  • Znajomość syslog, API, agentów, kolektorów, strumieniowania zdarzeń oraz procesów parsowania i wzbogacania
  • Wcześniejsza praca w skryptowaniu lub automatyzacji przy użyciu PowerShell, Python, REST API, Git, CI/CD lub infrastructure-as-code
  • Zrozumienie inżynierii detekcji, reakcji na incydenty, cyfrowej kryminalistyki oraz zabezpieczeń sieciowych
  • Znajomość języka angielskiego na poziomie min. B2

Mile widziane

  • Doświadczenie w regulowanych środowiskach infrastruktury krytycznej, energetyce lub OT
  • Znajomość NIS2, ISO/IEC 27001, IEC 62443 oraz wymagań dotyczących retencji logów bezpieczeństwa
  • Certyfikaty Microsoft, Splunk, GIAC, CISSP, CISM lub równoważne

Nr oferty JOB-E4BP6

Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.

Quick apply

Senior SIEM Engineer (f/m/x)

Work mode*

Choose at least one option

Option was not selected

angle-down

Option was not selected

Attach CV*

Uploaded file:
  • file_icon Created with Sketch.

Acceptable files: doc, docx, pdf. (max 5MB)
Please submit your file in DOC, DOCX or PDF format
The upload size is limited to 5 MB
File is empty
File was not uploaded

At any time, you may withdraw your consent to the processing of personal data, but such withdrawal shall not affect the legal compliance of any processing of such data, which had occurred before you withdrew your consent. Detailed information on the processing of your personal data is specified in the Privacy Policy.

Sii Poland follows the Procedure for reporting law violations.

Create MySii account to follow your application's status
success

Your application has been submitted

We will contact you as soon as we review your CV

Processing...

Sorry, something went wrong and your message was not delivered

Refresh the page and try again. Contact us, if problem occurs again

We’re sorry, but the selected file appears to be damaged and we can't process it.

Please try uploading a different copy or a new version of the file. Contact us, if problem occurs again.

Benefits for you

  • Great Place to Work
  • Solid financial situation
  • Contracts with the biggest brands
  • Centre of internal trainings
  • Many experts you can learn from
  • Open and accessible management team
  • Profit sharing
  • Passion Sponsorship program
  • Regular integration events and trips
  • Comfortable and well-equipped offices
  • MySii app
  • Medical care
Apply now Recommend a friend

Änderungen im Gange

Wir aktualisieren unsere deutsche Website. Wenn Sie die Sprache wechseln, wird Ihnen die vorherige Version angezeigt.

Ta treść jest dostępna tylko w jednej wersji językowej.
Nastąpi przekierowanie do strony głównej.

Czy chcesz opuścić tę stronę?

Einige Inhalte sind nicht in deutscher Sprache verfügbar.
Sie werden zur englischen Version der ausgewählten Seite weitergeleitet.

Möchten Sie fortfahren?

Einige Inhalte sind nicht in deutscher Sprache verfügbar.
Sie werden auf die deutsche Homepage weitergeleitet.

Möchten Sie fortsetzen?