SIEM Admin & Engineer — Threat Detection

Andersen Lab

Kraków

On-site

PLN 180,000 - 240,000

Full time

9 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Private health insurance
Sports compensation
Mentoring program
Corporate training portal
Referral program

Job summary

Andersen is seeking an experienced SIEM Administrator/Engineer to enhance a SIEM platform and support centralized security monitoring and threat detection. The role involves onboarding log sources, developing detection rules, and building SOAR playbooks within a multi-tenant environment.

Required hands-on SIEM experience (3+ years in production) and proficiency with leading platforms; English at Upper-Intermediate level or higher; background verification will be conducted.

Qualifications

  • 5+ years IT/cybersecurity experience.
  • 3+ years administering an enterprise SIEM in production.
  • Experience with major SIEM platforms (Microsoft Sentinel, Splunk ES, IBM QRadar, Elastic Security).
  • Hands-on log source onboarding, parsing and normalization (Syslog, CEF, WEF, API connectors).
  • Experience writing detection content in the platform query language (KQL, SPL, AQL).
  • Understanding of MITRE ATT&CK mapping for coverage.
  • Clean professional records and willingness to undergo background verification.
  • Level of English – Upper-Intermediate and above.

Responsibilities

  • Administering, maintaining and upgrading the SIEM platform, including health, performance, capacity and licensing.
  • Onboarding and normalizing new log sources in multi-tenant setups.
  • Developing, tuning and maintaining detection rules, correlation searches, dashboards and reports.
  • Reducing false positives with SOC analysts and implementing new use cases.
  • Building and maintaining SOAR playbooks and integrations.
  • Maintaining documentation, data retention policies and access control.
  • Supporting audits and compliance reporting.

Skills

SIEM administration
Threat detection
Log onboarding
Detection content
KQL/SPL/AQL
MITRE ATT&CK
English proficiency

Tools

Syslog
CEF
Windows Event Forwarding
APIs/log connectors

Job description

Andersen is seeking an experienced SIEM Administrator/Engineer to enhance a SIEM platform and support centralized security monitoring and threat detection. The role involves onboarding log sources, developing detection rules, and building SOAR playbooks within a multi-tenant environment.

Required hands-on SIEM experience (3+ years in production) and proficiency with leading platforms; English at Upper-Intermediate level or higher; background verification will be conducted.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SSIEM Administrator / Engineer
SSIEM Administrator / Engineer

Andersen Lab • Kraków

On-site
PLN 180,000 - 240,000
Private health insurance
Sports compensation
Mentoring program
+2
Senior Detection Engineer (SIEM/SOAR) — Remote & Flexible
Senior Detection Engineer (SIEM/SOAR) — Remote & Flexible

S-PRO • Polska

Hybrid
PLN 180,000 - 260,000
Flexible schedule
Remote work model
Medical insurance
+3
Senior SIEM Threat Detection & Security Ops Specialist
Senior SIEM Threat Detection & Security Ops Specialist

Talan • Warszawa

Hybrid
PLN 306,000 - 481,000
Remote Position
Training and career development
International projects
+1
Security Operations Engineer - Incident Response & SIEM
Security Operations Engineer - Incident Response & SIEM

Asana • Warszawa

Hybrid
PLN 285,740 - 400,130
Health insurance
Breakfast and lunch catering
Career growth budget
+3
Security Operations Analyst (SIEM Operations and Threat Detection)
Security Operations Analyst (SIEM Operations and Threat Detection)

Talan • Warszawa

Hybrid
PLN 306,000 - 481,000
Remote Position
Training and career development
International projects
+1
SIEM & SOAR Engineer — Hybrid/Remote Cybersecurity
SIEM & SOAR Engineer — Hybrid/Remote Cybersecurity

Ernst & Young Advisory Services Sdn Bhd • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid/Remote work
EY Badges
Career Counselor
+3
Detection Engineer (German-speaking)
Detection Engineer (German-speaking)

S-PRO • Polska

Hybrid
PLN 180,000 - 260,000
Flexible schedule
Remote work model
Medical insurance
+3
Senior Detection Engineer - SIEM & Threat Automation
Senior Detection Engineer - SIEM & Threat Automation

F5 Networks, Inc.  • Warszawa

On-site
PLN 180,000 - 240,000
Threat Response Engineer - Detection-as-Code & SIEM
Threat Response Engineer - Detection-as-Code & SIEM

Asana, Inc. • Warszawa

Hybrid
PLN 356,000 - 405,000
Health insurance with dental andTravel
Office-based with hybrid days
Lunch catering
+6
Senior Detection Engineer — Detection-as-Code
Senior Detection Engineer — Detection-as-Code

F5 • Warszawa

On-site
PLN 180,000 - 260,000