Security Engineer (SIEM)

Next Link
Barcelona, Spain
1 day ago
Apply on www.adzuna.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Application Programming Interfaces (APIs) Bash Shell Cyber Security Computer Programming Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell Security Information and Event Management Systems Integration Cyber Threat Analysis Microsoft Sentinel Api Management
+1 more
Servicenow

Job description

Inscribirse en esta oferta At NextLink, we are looking for a Senior Security Engineer (SIEM) to join our team and collaborate closely with one of our most recognized clients in the pharmaceutical sector. You will join the Cyber Intelligence & Security Operations Center (CISOC) team, focusing on security monitoring and detection capabilities through SIEM/XDR technologies. The role combines hands-on security engineering, use case development, automation, detection improvement, reporting, and collaboration with Security Detection, Incident Response, Risk, and Information Security teams. Main Responsibilities:

  • Design, implement, and continuously improve SIEM/XDR security use cases, including fine-tuning to reduce false positives.
  • Develop and maintain scripts, integrations, and APIs to enrich SIEM/XDR capabilities and automate security monitoring activities.
  • Support the implementation and maintenance of simulated threats / BAS scenarios to test and improve detection use cases.
  • Contribute to the evolution of security technologies in line with the defined roadmap and improve detection capabilities together with Security Detection and Incident Response teams.
  • Act as a point of contact for security monitoring reports and dashboards, presenting status and updates to technical experts and management.
  • Follow defined frameworks, processes, SOPs, and working instructions, ensuring compliant and up-to-date documentation.
  • Collaborate with Risk and Information Security teams on identified risks, remediation, prioritisation, analysis, triage, and security monitoring improvements.

Requirements

  • Proven hands-on experience with SIEM/XDR technologies and security monitoring/detection activities.
  • Experience developing and fine-tuning security detection use cases, ideally with technologies such as Microsoft Sentinel or Microsoft Defender.
  • Programming/scripting experience with Python, PowerShell, Bash, or similar, including API integrations.
  • Good understanding of security weaknesses, remediation processes, prioritization, change management, analysis, and triage.
  • Strong analytical thinking, problem-solving, communication, teamwork, agility, and results-oriented skills.
  • Excellent spoken and written English.
  • Experience working in virtual, international, and multicultural environments. Desirable Requirements

  • Experience with Breach & Attack Simulation (BAS) and simulated threat creation.
  • Experience with reporting and ticketing platforms such as ServiceNow.
  • Relevant SIEM/XDR certifications, particularly related to Microsoft Sentinel or Microsoft Defender, are a plus.
  • Security certifications such as Security+, CE, GCIH, ECIH, OSCP, or CEH are desirable but not mandatory.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all