> Markdown version of [/jobs/ext/1623585-cyber-defense-siem-integration-engineer](https://www.wearedevelopers.com/jobs/ext/1623585-cyber-defense-siem-integration-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defense SIEM Integration Engineer - **Company:** SIEMENS, S.A. - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Software Applications, Microsoft Azure, Command-Line Interface, Cloud Computing, Cloud Storage, Cyber Security, Linux, Intrusion Detection and Prevention, JSON, Python (Programming Language), Unix Shell, Log Analysis, Parsing, Regular Expressions, Logstash, Kusto Query Language, Syslog, Azure Service Bus, Data Ingestion, Cyber Threat Analysis, Information Technology, Microsoft Sentinel, Restful APIs, Terraform, Azure Resource Manager, Key Vault - **Published:** July 14, 2026 - **Apply:** https://www.jobleads.com/es/job/ef49300cd0b7482528cbe151657407c3b ## About the Role * Overall experience in security monitoring/security operations center environments (SOCs) and with their underlying processes. * Good understanding of the cybersecurity landscape, including standards, frameworks, and best practices. * Strong knowledge of Logstash, including plugin configuration and pipeline optimization. * Experience onboarding logs from various sources using industry-standard tools and formats (e.g., Syslog, JSON, REST APIs). * Experience with regular expressions and Grok-based parsing. * Familiarity with cloud platforms, especially Microsoft Azure, including experience with: * Sentinel and Log Analytics / KQL * Azure Monitor and integration of Azure Monitor Agent for Linux * Designing and implementing infrastructure supporting Sentinel data ingestion (e.g. Event Hubs, Storage Accounts, Key Vault, etc) * Deployment of workloads in Azure Container Instances (e.g., Logstash, Python) * IaC with Terraform / OpenTofu * Knowledge of syslog forwarding and ingestion using Azure VMs with AMA or other hybrid solutions. * Comfortable with the Linux shell and command-line tools. * Strong technical documentation writing skills. * University degree (or equivalent experience) in computer science, IT security, or related fields. * Proficiency in written and spoken English, with excellent interpersonal and collaborative skills. * Willingness to build up and share your technical knowledge. * Ability to communicate clearly and effectively with peers, partners, and customers ## Description * Collaborate with different defense teams (like Security Analysts, Threat Hunting, Incident Response, Data Science, SecDevOps, Threat Intelligence) to help create high quality Threat Detection for IT applications and application logs. * Identify and onboard relevant log sources and detection components, including both on-premises and Azure-native sources. * Implement and manage Azure resources and integrations for the ingestion of log sources into Microsoft Sentinel. * Develop log parsers using Logstash Grok expressions to normalize and enrich data from various sources, with adherence to the Elastic Common Schema (ECS) format. * Support strategic service planning by advising on best-suited detection and integration technologies, with a focus on Azure-native solutions and scalability. * Assist in the administration and automation of tools and services within hybrid environments. * Actively participate in monitoring-driven Incident and Problem Management processes. * Contribute to internal knowledge creation and the sharing of best practices related to Azure and Sentinel architecture, data ingestion, and automation. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) ## Related Articles - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)