Security Engineer (SIEM)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Inscribirse en esta oferta At NextLink, we are looking for a Senior Security Engineer (SIEM) to join our team and collaborate closely with one of our most recognized clients in the pharmaceutical sector. You will join the Cyber Intelligence & Security Operations Center (CISOC) team, focusing on security monitoring and detection capabilities through SIEM/XDR technologies. The role combines hands-on security engineering, use case development, automation, detection improvement, reporting, and collaboration with Security Detection, Incident Response, Risk, and Information Security teams. Main Responsibilities:
- Design, implement, and continuously improve SIEM/XDR security use cases, including fine-tuning to reduce false positives.
- Develop and maintain scripts, integrations, and APIs to enrich SIEM/XDR capabilities and automate security monitoring activities.
- Support the implementation and maintenance of simulated threats / BAS scenarios to test and improve detection use cases.
- Contribute to the evolution of security technologies in line with the defined roadmap and improve detection capabilities together with Security Detection and Incident Response teams.
- Act as a point of contact for security monitoring reports and dashboards, presenting status and updates to technical experts and management.
- Follow defined frameworks, processes, SOPs, and working instructions, ensuring compliant and up-to-date documentation.
- Collaborate with Risk and Information Security teams on identified risks, remediation, prioritisation, analysis, triage, and security monitoring improvements.
Requirements
- Proven hands-on experience with SIEM/XDR technologies and security monitoring/detection activities.
- Experience developing and fine-tuning security detection use cases, ideally with technologies such as Microsoft Sentinel or Microsoft Defender.
- Programming/scripting experience with Python, PowerShell, Bash, or similar, including API integrations.
- Good understanding of security weaknesses, remediation processes, prioritization, change management, analysis, and triage.
- Strong analytical thinking, problem-solving, communication, teamwork, agility, and results-oriented skills.
- Excellent spoken and written English.
-
Experience working in virtual, international, and multicultural environments. Desirable Requirements
- Experience with Breach & Attack Simulation (BAS) and simulated threat creation.
- Experience with reporting and ticketing platforms such as ServiceNow.
- Relevant SIEM/XDR certifications, particularly related to Microsoft Sentinel or Microsoft Defender, are a plus.
- Security certifications such as Security+, CE, GCIH, ECIH, OSCP, or CEH are desirable but not mandatory.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Top-Paying Tech Jobs (with Salaries)
9 Ways to Make Money Hacking
Is Software Engineering Over-Saturated?
Where To Find Software Engineering Jobs