> Markdown version of [/jobs/ext/3649807-senior-security-engineer-siem-rdt-security-platforms](https://www.wearedevelopers.com/jobs/ext/3649807-senior-security-engineer-siem-rdt-security-platforms). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer (Siem) - Rdt Security Platforms - **Company:** Roche - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Cyber Security, Data Transport Utility, DevOps, Github, Python (Programming Language), Networking Basics, Ansible, Security Log, Security Information and Event Management, Data Streaming, TCP/IP, Software Vulnerability Management, Data Logging, Load Balancing, System Availability, Large Language Models, Prompt Engineering, Indexer, Firewalls (Computer Science), Infrastructure as Code (IaC), Agentic-AI, Enterprise Integration, Restful APIs, Model Context Protocol, Splunk, Api Management, Vulnerability Analysis - **Published:** October 9, 2026 - **Apply:** https://www.buscojobs.com.es/senior-security-engineer-siem-rdt-security-platforms-en-madrid-ID-374893156 ## About the Role Security Service Depth: Deep conceptual understanding of the SIEM/Log Management lifecycle (Collection, Indexing, Storage, Retention and Searching) and Vulnerability Management. Networking Fundamentals: Expert understanding of networking (TCP/IP, Load Balancing, Firewalls) as it relates to high-volume security data transport. Coding & API Mastery: Strong experience with Python and interacting with complex REST APIs. Proven ability to interconnect disparate technologies via APIs and custom integrations. Modern DevOps: Strong experience with Ansible and GitHub for managing infrastructure. Advanced AI/Automation: Proven experience or deep project work building Agentic AI workflows. Practical expertise in MCP (Model Context Protocol) or building custom LLM-based tools to automate technical tasks. Tooling (Preferred) Experience with Cribl, Splunk, or Tenable is a plus, but the ability to rapidly upscale and automate these via AI is essential. ## Description Senior Security EngineerThe MissionYou will be a key member of the SIEM team, contributing to the engineering and strategic evolution of our global Security Log Management and Vulnerability Scanning services.This is an end-to-end ownership role: from defining the roadmap and architectural strategy to hands-on engineering and operational excellence.Key ResponsibilitiesService Ownership & Strategy: Drive the end-to-end lifecycle of our Security Log Management (Splunk & Cribl) and Security Scanning (Tenable) platforms.Service Reliability: Ensure high availability and performance of our security services globally, acting as an escalation point for complex technical challenges.System Interconnectivity: Develop and manage sophisticated API integrations to ensure seamless data flow between the security scanning (Tenable) and logging (Splunk/Cribl) tiers.Next-Gen Security Log Architecture: Drive the transition from a traditional "index-all" logging approach to a "data-tiering" mindset.Focus on cost optimization and performance across all data lifecycle phases: routing, filtering, storing and searching, ensuring security data is accessible and cost-effective.Infrastructure as Code (IaC): Orchestrate the evolution of our security infrastructure by managing all configurations via CI/CD pipelines (GitHub, Ansible, and Python), ensuring a fully automated and version-controlled environment.AI-Augmented Engineering: Actively integrate AI Agents and MCP (Model Context Protocol) servers into daily operations.Build agentic AI workflows to automate configuration, troubleshooting, and complex interconnectivity, while improving service offerings and user experience.Mentorship: Act as a technical catalyst for the team, mentoring colleagues in prompt engineering, agentic AI development, and advanced AI ecosystems.Technical Leadership: Serve as a technical lead, defining implementation plans and driving continuous process improvements.Stakeholder Engagement: Effectively manage relationships across functional teams, acting as a clear communicator and advisor to ensure alignment on security goals and project delivery.Technical Requirements & ExpertiseSecurity Service Depth: Deep conceptual understanding of the SIEM/Log Management lifecycle (Collection, Indexing, Storage, Retention and Searching) and Vulnerability Management.Networking Fundamentals: Expert understanding of networking (TCP/IP, Load Balancing, Firewalls) as it relates to high-volume security data transport.Coding & API Mastery: Strong experience with Python and interacting with complex REST APIs.Proven ability to interconnect disparate technologies via APIs and custom integrations.Modern DevOps: Strong experience with Ansible and GitHub for managing infrastructure.Advanced AI/Automation: Proven experience or deep project work building Agentic AI workflows.Practical expertise in MCP (Model Context Protocol) or building custom LLM-based tools to automate technical tasks.Tooling (Preferred)Experience with Cribl, Splunk, or Tenable is a plus, but the ability to rapidly upscale and automate these via AI is essential.Equal Opportunity StatementRoche is an Equal Opportunity Employer.We believe it's urgent to deliver medical solutions right now - even as we develop innovations for the future.#J-*****-Ljbffr