IT SIEM Engineer

SII Group Switzerland

Bezirk Olten

Vor Ort

CHF 110.000 - 170.000

Vollzeit

Vor 7 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

SII Group Switzerland is seeking an IT SIEM Engineer to design, deploy, and operate monitoring for critical IT environments. You will onboard logs, build data pipelines, and ensure reliable security visibility across identity, endpoints, cloud, and applications.

Ideal candidates have hands-on SIEM experience with MS Sentinel, Splunk, or QRadar, plus scripting skills and strong English. The role emphasizes collaboration across IT, security, and cloud teams in a global setup.

Qualifikationen

  • Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering.
  • Hands-on experience with enterprise SIEMs, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps also relevant.
  • Experience onboarding and troubleshooting logs across Windows, Linux, Entra ID, cloud, network, endpoint, and application environments.
  • Proficiency in KQL, SPL, SQL, or similar query languages, with analytics and performance troubleshooting.
  • Knowledge of syslog, APIs, agents, collectors, event streaming, parsing, normalization, and enrichment.
  • Scripting/automation skills with PowerShell, Python, REST APIs, Git, CI/CD, or IaC.
  • Understanding of detection engineering, incident response, forensics, networking, security controls, and data protection.
  • Strong analytical, documentation, communication, and ownership skills; professional English required.
  • Knowledge of SIEM/data lake architecture, SOAR, detection-as-code, and regulated/critical infrastructure or OT environments.

Aufgaben

  • Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure.
  • Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments.
  • Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment.
  • Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures.
  • Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing.
  • Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility.
  • Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records.
  • Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution.
  • Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers.

Kenntnisse

SIEM engineering
Security monitoring
Log management
Microsoft Sentinel
Splunk
QRadar
Elastic
Query languages
Scripting: PowerShell
Python
REST APIs
Git/CI/CD/IaC
English communication

Tools

Microsoft Sentinel
Splunk
QRadar
Elastic
Google SecOps

Jobbeschreibung

SII Group is a trusted technology partner, SII provides high value added solutions for the IT projects of many large corporations. Since its founding in 1979, the Company has been providing solutions adapted to its clients’ needs, by relying on :

> Its acknowledged expertise in various industries and sectors

> Proven 'turnkey' solutions

> Adaptable, evolving services

Today, with a staff of more than 18'000, SII Group is supporting companies across 20 countries.

At SII Switzerland we pay attention to the personal and professional wellbeing of our employees. We place our collaborators at the heart of our actions and activities. If you are motivated by the perspective of joining a big, trusted and recognized group, then let's meet !

To develop our consulting offer and support one of our clients, we are looking for a talented IT SIEM Engineer.

Missions
  • Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure.
  • Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments.
  • Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment.
  • Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures.
  • Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing.
  • Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility.
  • Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records.
  • Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution.
  • Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers.
Profile
  • Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering.
  • Hands-on experience with enterprise SIEMs, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps also relevant.
  • Experience onboarding and troubleshooting logs across Windows, Linux, Entra ID, cloud, network, endpoint, and application environments.
  • Proficiency in KQL, SPL, SQL, or similar query languages, with analytics and performance troubleshooting.
  • Knowledge of syslog, APIs, agents, collectors, event streaming, parsing, normalization, and enrichment.
  • Scripting/automation skills with PowerShell, Python, REST APIs, Git, CI/CD, or IaC.
  • Understanding of detection engineering, incident response, forensics, networking, security controls, and data protection.
  • Strong analytical, documentation, communication, and ownership skills; professional English required.
  • Knowledge of SIEM/data lake architecture, SOAR, detection-as-code, and regulated/critical infrastructure or OT environments.
  • Familiarity with NIS2, ISO 27001, IEC 62443, log retention requirements, and relevant security certifications.
For information
  • Location: remote from Switzerland
  • Languages: Fluent English, German is a plus
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Remote SIEM Engineer - Security Analytics & Onboarding
Remote SIEM Engineer - Security Analytics & Onboarding

SII Group Switzerland • Bezirk Olten

Vor Ort
CHF 110.000 - 170.000
GxP IT Infrastructure & Systems Administrator
GxP IT Infrastructure & Systems Administrator

SII Group Switzerland • Zürich

Vor Ort
CHF 90.000 - 120.000
Remote IT Infrastructure Security Engineer
Remote IT Infrastructure Security Engineer

SII Group Switzerland • Bezirk Olten

Vor Ort
CHF 120.000 - 160.000
IAM Technical Expert
IAM Technical Expert

SII Group Switzerland • Lausanne

Vor Ort
CHF 120.000 - 170.000
GxP IT Infrastructure & Systems Administrator
GxP IT Infrastructure & Systems Administrator

SII Group Switzerland • Sankt Gallen

Vor Ort
CHF 90.000 - 130.000
Intermediate Security Engineer Logging SIEM Data Pipelines 100% (f/m/d)
Intermediate Security Engineer Logging SIEM Data Pipelines 100% (f/m/d)

Bank Julius Bär & Co. Ltd. • Zürich

Vor Ort
CHF 100.000 - 130.000
IT Security Engineer – Infrastructure & Industrial Security
IT Security Engineer – Infrastructure & Industrial Security

Helvetica Partners • Bern

Hybrid
CHF 110.000 - 170.000
Network Engineer
Network Engineer

Jobup • Prilly

Vor Ort
CHF 90.000 - 130.000
Product & Solution Security Expert 80-100%
Product & Solution Security Expert 80-100%

Siemens • Zug

Hybrid
CHF 150.000 - 190.000
Hybrid work model
Mobility stipend
Training opportunities
+1
Analyste CSIRT - Cybersécurité
Analyste CSIRT - Cybersécurité

Experis • Lancy

Vor Ort
CHF 130.000 - 190.000