SSIEM Administrator / Engineer

Andersen Lab

Kraków

On-site

PLN 180,000 - 240,000

Full time

8 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Private health insurance
Sports compensation
Mentoring program
Corporate training portal
Referral program

Job summary

Andersen is seeking an experienced SIEM Administrator/Engineer to enhance a SIEM platform and support centralized security monitoring and threat detection. The role involves onboarding log sources, developing detection rules, and building SOAR playbooks within a multi-tenant environment.

Required hands-on SIEM experience (3+ years in production) and proficiency with leading platforms; English at Upper-Intermediate level or higher; background verification will be conducted.

Qualifications

  • 5+ years IT/cybersecurity experience.
  • 3+ years administering an enterprise SIEM in production.
  • Experience with major SIEM platforms (Microsoft Sentinel, Splunk ES, IBM QRadar, Elastic Security).
  • Hands-on log source onboarding, parsing and normalization (Syslog, CEF, WEF, API connectors).
  • Experience writing detection content in the platform query language (KQL, SPL, AQL).
  • Understanding of MITRE ATT&CK mapping for coverage.
  • Clean professional records and willingness to undergo background verification.
  • Level of English – Upper-Intermediate and above.

Responsibilities

  • Administering, maintaining and upgrading the SIEM platform, including health, performance, capacity and licensing.
  • Onboarding and normalizing new log sources in multi-tenant setups.
  • Developing, tuning and maintaining detection rules, correlation searches, dashboards and reports.
  • Reducing false positives with SOC analysts and implementing new use cases.
  • Building and maintaining SOAR playbooks and integrations.
  • Maintaining documentation, data retention policies and access control.
  • Supporting audits and compliance reporting.

Skills

SIEM administration
Threat detection
Log onboarding
Detection content
KQL/SPL/AQL
MITRE ATT&CK
English proficiency

Tools

Syslog
CEF
Windows Event Forwarding
APIs/log connectors

Job description

Andersen is hiring a SIEM Administrator / Engineer for a project enhancing a SIEM platform and supporting centralized security monitoring and threat detection.

Our customer is a technology and consulting organization providing digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support. It helps organizations modernize complex technology environments, strengthen security, and improve the reliability and scalability of their digital operations. By combining technical expertise with modern technologies and service-oriented delivery, the company supports digital transformation, operational efficiency, and the continuous improvement of critical IT systems across multiple markets.

The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment. It includes managing and enhancing the SIEM platform to support centralized security monitoring, threat detection, and reliable cyber defense operations across multiple organizations worldwide.

Responsibilities:
  • Administering, maintaining and upgrading the SIEM platform, including health, performance, capacity and licensing.
  • Onboarding and normalizing new log sources (network, endpoint, cloud, identity, applications), including in multi-tenant setups.
  • Developing, tuning and maintaining detection rules, correlation searches, dashboards and reports.
  • Reducing false positives together with SOC analysts and implementing new use cases.
  • Building and maintaining SOAR playbooks and integrations.
  • Maintaining documentation, data retention policies and access control.
  • Supporting audits and compliance reporting.
Requirements:
  • Experience in IT or cybersecurity for 5+ years, including 3+ years administering an enterprise SIEM in production.
  • Deep hands-on experience with at least one major SIEM: Microsoft Sentinel, Splunk ES, IBM QRadar or Elastic Security.
  • Hands-on experience with log source onboarding, parsing, and normalization using Syslog, CEF, Windows Event Forwarding (WEF), and API-based cloud connectors.
  • Experience writing detection content in the platform's query language (KQL, SPL, AQL or equivalent).
  • Understanding of MITRE ATT&CK for mapping detection coverage.
  • Clean professional records and willingness to undergo background verification.
  • Level of English – from Upper-Intermediate and above.
Nice-to-haves:
  • SOAR experience (Sentinel Logic Apps, Splunk SOAR, Cortex XSOAR).
  • Multi-tenant SIEM or MSSP experience.
  • Experience in scripting and automation (Python, PowerShell) and Infrastructure as Code.
  • Experience working with detection-as-code practices (Sigma, Git-based rule management).
Reasons why this job would be interesting to you:
  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Your personal data is protected in accordance with GDPR regulations. Learn more: https://andersenlab.com/privacy-policy/pl

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Management Consultant
Vulnerability Management Consultant

Andersen Lab • Polska

On-site
PLN 140,000 - 210,000
Private health insurance
Sports compensation
Mentoring programs
DevSecOps Architect / Technical Lead
DevSecOps Architect / Technical Lead

DOU Polska • Warszawa

Hybrid
PLN 180,000 - 280,000
Private health insurance and sports
Certification compensation
Referral program
+2
SIEM Admin & Engineer — Threat Detection
SIEM Admin & Engineer — Threat Detection

Andersen Lab • Kraków

On-site
PLN 180,000 - 240,000
Private health insurance
Sports compensation
Mentoring program
+2
Penetration Tester
Penetration Tester

Andersen Lab • Polska

Hybrid
PLN 120,000 - 190,000
Private health insurance
Sports compensation
Remote/hybrid work options
Detection Engineer (German-speaking)
Detection Engineer (German-speaking)

S-PRO • Polska

Hybrid
PLN 180,000 - 260,000
Flexible schedule
Remote work model
Medical insurance
+3
Security Operations Analyst (SIEM Operations and Threat Detection)
Security Operations Analyst (SIEM Operations and Threat Detection)

Talan • Warszawa

Hybrid
PLN 306,000 - 481,000
Remote Position
Training and career development
International projects
+1
Data Engineer
Data Engineer

Andersen • Poland

On-site
USD 120,000 - 180,000
Remote Cybersecurity Architect: SIEM & SOC Lead (German)
Remote Cybersecurity Architect: SIEM & SOC Lead (German)

Experis ManpowerGroup Sp. z o.o. • Poland

On-site
PLN 180,000 - 240,000
DFIR Analyst
DFIR Analyst

SentinelOne • Poland

On-site
PLN 120,000 - 180,000
RSUs
ESPP
Competitive leave benefits
+6
Cyber Security Architect
Cyber Security Architect

Experis ManpowerGroup Sp. z o.o. • Warszawa

On-site
PLN 180,000 - 300,000
Multisport Card
Life insurance
Private healthcare
+1