Specialist SIEM Engineering & Incident Response (Mainz, RP, DE, 55131)

Biopharma Careers

Mainz

Vor Ort

EUR 70.000 - 100.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Company bike
Job ticket
Deutschlandticket
Employer-funded pension
Childcare

Zusammenfassung

BioNTech Mainz is seeking a Specialist SIEM Engineering & Incident Response to support CSIRT operations, focusing on SIEM onboarding, connector health, and monitoring. You will enhance Microsoft Sentinel and Defender integrations, assist with phishing analysis and incident investigations, and work with stakeholders to meet logging requirements.

Ideal candidates have several years in IT security operations, hands-on Sentinel/Defender experience, and a proactive approach to threat hunting and data

Qualifikationen

  • Bachelor’s degree or equivalent practical experience in Information Security, Computer Science, or related field.
  • Several years of IT security operations, SIEM engineering, SOC, or related monitoring roles.
  • Hands-on experience with Microsoft Sentinel and Defender integrations, connectors, and data onboarding.
  • Experience with log analysis, event correlation, and integrating enterprise systems into SIEM.
  • Basic forensics or incident investigation support experience preferred.
  • Interest in threat hunting, security analytics, and proactive detection improvement.
  • Ability to translate stakeholder needs into concrete monitoring use cases.
  • Understanding of IT systems, apps, interfaces, and dependencies relevant to security monitoring.
  • Strong documentation, process definition, and service-oriented mindset.
  • Familiarity with SIEM data flows and monitoring health indicators.

Aufgaben

  • Perform daily security operations tasks including phishing analysis, escalated security incidents, and incident response support.
  • Act as L3 support for incidents escalated by external MSSP SOC provider and contribute to investigation and response.
  • Maintain, improve, troubleshoot, and expand Microsoft Sentinel and Defender connectors and data onboarding.
  • Monitor SIEM and related security platform health, ingestion status, data quality, and service reliability.
  • Analyze SIEM data consumption and support optimization of data onboarding and monitoring effectiveness.
  • Serve as contact for stakeholders with SIEM requirements, including KRITIS-related systems.
  • Define intake processes for owners to report onboarding and monitoring requirements to CSIRT.
  • Support basic forensic activities: evidence collection, log review, and preservation per procedures.
  • Perform threat hunting using Defender and Sentinel capabilities, including workbooks and enrichment.
  • Contribute to continuous improvement of security monitoring coverage and operations.

Kenntnisse

SIEM engineering
Incident response
Microsoft Sentinel
Microsoft Defender
KQL
Log analysis
Threat hunting
Stakeholder management

Ausbildung

Bachelor’s degree in Information Security / Computer Science

Tools

MS Defender connectors
Data onboarding

Jobbeschreibung

Mainz, Germany | full time | Job ID: 11706

About the role:

As Specialist SIEM Engineering & Incident Response you are responsible for supporting our CSIRT operations with a focus on SIEM onboarding, connector health, operational monitoring, stakeholder enablement, and foundational forensic and threat hunting capabilities. The role combines shared daily security operations responsibilities with technical ownership for improving Microsoft Sentinel and Defender integrations, maintaining SIEM service quality, and supporting business stakeholders with specific logging and monitoring requirements.

In addition, this role contributes to daily operational activities such as phishing analysis, incident investigation, escalated SOC case handling, third-party incident assessments, and incident response support.

Your contribution:
  • Perform daily security operations tasks, including analysis of phishing emails, handling of escalated security incidents, and support for incident response activities
  • Act as L3 support for incidents escalated by the external MSSP SOC provider and contribute to investigation, coordination, and response activities
  • Maintain, improve, troubleshoot, and expand Microsoft Sentinel and Microsoft Defender connectors, data integrations, and onboarding of relevant log sources
  • Monitor SIEM and related security platform health, including connectors, tables, automations, ingestion status, data quality, and service reliability
  • Analyze SIEM data consumption and support optimization of data onboarding, cost efficiency, and monitoring effectiveness
  • Serve as contact person for business and technical stakeholders with specific SIEM and monitoring requirements, including KRITIS-related applications and other critical systems
  • Define and establish clear guidelines and intake processes for system owners and stakeholders to report onboarding, monitoring, and use case requirements to the CSIRT team
  • Support basic forensic activities, including initial evidence collection, log review, timeline support, and preservation of relevant information in line with internal procedures
  • Perform basic threat hunting activities using Microsoft Defender and Sentinel capabilities, including workbooks, threat intelligence enrichment, data exploration, and hypothesis-driven analysis
  • Contribute to the continuous improvement of security monitoring coverage, visibility, documentation, and operational processes
A good match:
  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or a comparable field; alternatively, equivalent practical experience
  • Several years of experience in IT security operations, SIEM engineering, SOC, or related security monitoring functions
  • Hands-on experience with Microsoft Sentinel and/or Microsoft Defender, especially in connector management, data onboarding, monitoring, and troubleshooting
  • Experience with log analysis, event correlation, and integration of enterprise systems into SIEM platforms
  • Basic practical experience in digital forensics, incident investigation support, or evidence handling
  • Initial experience or strong interest in threat hunting, security analytics, and proactive detection improvement
  • Experience working with internal stakeholders to gather technical requirements and translate them into monitoring or security use cases
  • Understanding of enterprise IT systems, application landscapes, interfaces, and dependencies relevant for security monitoring
  • Experience with documentation, process definition, and service-oriented operational support is beneficial
  • Strong knowledge of SIEM data flows, connector architectures, log source onboarding, and monitoring health indicators
  • Familiarity with KQL, workbook creation, and Microsoft security ecosystem capabilities
  • Basic understanding of forensic principles, chain of custody, and evidence preservation
  • Ability to translate stakeholder requirements into structured technical implementation steps
  • Strong organizational skills and a structured, service-oriented way of working
  • Good communication skills for interaction with system owners, business stakeholders, and external providers
  • Analytical mindset with attention to detail and a focus on operational quality
  • Security certifications such as SC-200, BTL1, AZ-500, GCFA (basic exposure), or similar are beneficial
Your Benefits:

It's our priority to support you:

  • Your flexibility: flexible hours |vacation account
  • Your growth: Digital Learning | Performance & talent development | leadership development | Apprenticeships | LinkedIn Learning
  • Your value: Your voice at the table | Culture on an equal footing | Opportunities to shape & impact | Support for your full potential
  • Your health and lifestyle: Company bike
  • Your mobility: Job ticket | Deutschlandticket
  • Your life phases: Employer-funded pension | Childcare

Job ID 11706(please always specify if you have any questions)

By submitting your application, you acknowledge that a background check will be conducted as part of the recruitment process in accordance with applicable laws and regulations. If you are considered for the position, BioNTech will conduct the background check through our service provider ‘HireRight’. You will be informed accordingly by your BioNTech-Recruiter.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

IT Security Engineer SOC/SIEM
IT Security Engineer SOC/SIEM

Tenth Revolution Group • Ratingen

Hybrid
EUR 70.000 - 100.000
Attraktives Gehalt
Hybrides Arbeitsmodell
Weiterbildungs- und Entwicklungsmöglic
System Engineer Digital Solutions R&D (2-year fixed-term contract) (Mainz, RP, DE, 55116)
System Engineer Digital Solutions R&D (2-year fixed-term contract) (Mainz, RP, DE, 55116)

Biopharma Careers • Mainz

Vor Ort
EUR 70.000 - 100.000
Flexible hours
Vacation account
Digital Learning
+6
SOC Security Analyst: Incident Response & Threat Hunting
SOC Security Analyst: Incident Response & Threat Hunting

Nexa Global • Deutschland

Remote
USD 80.000 - 110.000
30 days of vacation
Training and certification opportunities
Special leave on Christmas Eve & New Year's Eve
Manager Business Risk & Compliance (Mainz, RP, DE, 55131)
Manager Business Risk & Compliance (Mainz, RP, DE, 55131)

Biopharma Careers • Mainz

Vor Ort
EUR 90.000 - 130.000
Flexible hours
Vacation account
Digital Learning
+6
Senior IT Security Engineer - SOC & SIEM
Senior IT Security Engineer - SOC & SIEM

Block MB • Düsseldorf

Hybrid
EUR 70.000 - 80.000
50 % Homeoffice
Deutschlandticket
Jobradleasing
+1
Senior Compliance Engineer (Mainz, RP, DE, 55131)
Senior Compliance Engineer (Mainz, RP, DE, 55131)

Biopharma Careers • Mainz

Vor Ort
EUR 80.000 - 100.000
Company bike
Job ticket
Associate Director AI Security (Mainz, RP, DE, 55131)
Associate Director AI Security (Mainz, RP, DE, 55131)

Biopharma Careers • Mainz

Vor Ort
EUR 150.000 - 210.000
Flexible hours
Vacation account
Digital Learning
+8
Security Operations Center Lead (m/f/x) onsite / remote in Germany
Security Operations Center Lead (m/f/x) onsite / remote in Germany

Scalable Capital • München

Hybrid
EUR 80.000 - 100.000
Flexible vacation policy
50% contribution for Deutschland Jobticket
Complimentary subscription to PRIME+ Broker
+2
(Senior) Consultant Cyber Security SIEM & SOC (all genders)
(Senior) Consultant Cyber Security SIEM & SOC (all genders)

Wavestone Poland Sp. z o.o. • Deutschland

Hybrid
EUR 90.000 - 130.000
Flexible Arbeitszeiten
30 Tage Urlaub
Mobiles Arbeiten innerhalb EU/UK
IT Security specialist
IT Security specialist

Nexa Global • Deutschland

Vor Ort
USD 80.000 - 110.000
30 days of vacation
Training and certification opportunities
Special leave on Christmas Eve & New Year's Eve