SIEM Integration Engineer - Azure (m/f/d)

Siemens

Amadora

Híbrido

EUR 60 000 - 90 000

Tempo integral

há 3 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Recebe uma resposta deste empregador — um currículo e uma carta de apresentação adaptados exatamente ao que estão a contratar.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Hybrid work
Health insurance
Online learning
Shuttle service

Resumo da oferta

Siemens is seeking a Cyber Defense Center SIEM Integration Engineer to design and implement scalable, secure solutions for large data volumes across hybrid environments. You will contribute to the Siemens Cyber Defense Center’s mission to defend against cyber security threats worldwide.

In this role you will collaborate with Security Analysts, Threat Hunting, Incident Response, Data Science, SecDevOps and Threat Intelligence to onboard log sources, build Logstash parsers (Grok) per ECS, and

Qualificações

  • University degree (or equivalent) in computer science, IT security, or related fields.
  • Experience in security monitoring/SOC environments and their processes.
  • Strong knowledge of Logstash, including Grok parsing and pipeline optimization.
  • Experience onboarding logs from diverse sources (Syslog, JSON, REST APIs).
  • Familiarity with cloud platforms, especially Microsoft Azure (Sentinel, Log Analytics, KQL).
  • Proficiency with IaC (Terraform/OpenTofu) and Azure infrastructure for data ingestion.
  • Ability to write strong technical documentation and communicate clearly.
  • Good English written and spoken; collaborative mindset.

Responsabilidades

  • Collaborate with defense teams to create high-quality threat detection for IT applications and logs.
  • Identify and onboard relevant log sources, both on-premises and Azure-native.
  • Implement and manage Azure resources to ingest data into Microsoft Sentinel.
  • Develop log parsers with Logstash Grok expressions to normalize data to ECS.
  • Advise on detection technologies and Azure-native solutions for scalability.
  • Assist in administration and automation within hybrid environments.
  • Participate in monitoring-driven Incident and Problem Management.
  • Share knowledge on Azure, Sentinel architecture, data ingestion, and automation.

Conhecimentos

Grok parsing
Logstash
Regex
Security monitoring
Azure Sentinel knowledge
English communication
SOC processes
Threat detection

Formação académica

Bachelor's degree in computer science or IT security

Ferramentas

Azure Sentinel
Azure Monitor
Log Analytics
Event Hubs
Storage Accounts
Key Vault
Azure Container Instances
Terraform/OpenTofu
Linux
AMA / Azure Monitor Agent
Python

Descrição da oferta de emprego

The Cyber Defense SIEM Integration Engineer is a member of the Siemens Cyber Defense Center, whose primary mission is to defend Siemens against cyber security threats worldwide.

You will help design and implement technical solutions with state-of-the-art tools capable of handling large volumes of data where scalability, consistency, security, and maintainability are key.

Come join us and let’s build reliable, performant, and secure systems together!

In this role, you will:
  • Collaborate with different defense teams (like Security Analysts, Threat Hunting, Incident Response, Data Science, SecDevOps, Threat Intelligence) to help create high quality Threat Detection for IT applications and application logs.
  • Identify and onboard relevant log sources and detection components, including both on-premises and Azure-native sources.
  • Implement and manage Azure resources and integrations for the ingestion of log sources into Microsoft Sentinel.
  • Develop log parsers using Logstash Grok expressions to normalize and enrich data from various sources, with adherence to the Elastic Common Schema (ECS) format.
  • Support strategic service planning by advising on best-suited detection and integration technologies, with a focus on Azure-native solutions and scalability.
  • Assist in the administration and automation of tools and services within hybrid environments.
  • Actively participate in monitoring-driven Incident and Problem Management processes.
  • Contribute to internal knowledge creation and the sharing of best practices related to Azure and Sentinel architecture, data ingestion, and automation.
What do you need to qualify for this job?
  • Overall experience in security monitoring/security operations center environments (SOCs) and with their underlying processes.
  • Good understanding of the cybersecurity landscape, including standards, frameworks, and best practices.
  • Strong knowledge of Logstash, including plugin configuration and pipeline optimization.
  • Experience onboarding logs from various sources using industrystandard tools and formats (e.g., Syslog, JSON, REST APIs).
  • Experience with regular expressions and Grok-based parsing.
  • Familiarity with cloud platforms, especially Microsoft Azure, including experience with:
    • Sentinel and Log Analytics / KQL
    • Azure Monitor and integration of Azure Monitor Agent for Linux
    • Designing and implementing infrastructure supporting Sentinel data ingestion (e.g. Event Hubs, Storage Accounts, Key Vault, etc)
    • Azure-native automation (e.g., Logic Apps & Functions)
    • Deployment of workloads in Azure Container Instances (e.g., Logstash, Python)
    • IaC with Terraform / OpenTofu
  • Knowledge of syslog forwarding and ingestion using Azure VMs with AMA or other hybrid solutions.
  • Comfortable with the Linux shell and command-line tools.
  • Strong technical documentation writing skills.
  • University degree (or equivalent experience) in computer science, IT security, or related fields.
  • Proficiency in written and spoken English, with excellent interpersonal and collaborative skills.
  • Willingness to build up and share your technical knowledge.
  • Ability to communicate clearly and effectively with peers, partners, and customers
What do we offer?
  • A hybrid and flexible working model to promote a better work-life balance, along with a budget for home office support and the opportunity to do 16 hours a year of volunteer work.
  • A health insurance, access to our on-site medical center, plus the chance to join sports groups.
  • In addition, you'll have access to online learning platforms and discounts with our partners.
  • A shuttle bus to commute to the facilities and the possibility of financial support to your studies.

At Siemens, we promote equal opportunities for all individuals, regardless of gender, identity, sexual orientation, ethnicity, age, (dis)ability, neurodiversity, or any other characteristic. We believe that diversity drives our success, and we strive to create an inclusive environment where everyone feels a sense of belonging and has the opportunity to grow and develop professionally.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Cyber Defense Center Analyst (m/f/d)
Cyber Defense Center Analyst (m/f/d)

Siemens • Lisboa

Presencial
EUR 50 000 - 70 000
Cyber Defense Center Analyst (m/f/d)
Cyber Defense Center Analyst (m/f/d)

Siemens • Amadora

Presencial
EUR 45 000 - 75 000
Cyber Defense Center Analyst
Cyber Defense Center Analyst

Siemens • Lisboa

Presencial
EUR 45 000 - 65 000
Cybersecurity Expert IT/OT (m/f/d)
Cybersecurity Expert IT/OT (m/f/d)

Siemens Mobility • Amadora

Híbrido
EUR 60 000 - 80 000
Flexible working
Health insurance
On-site medical center
+4
Application Manager - Cybersecurity, Compliance and Application Governance (m/f/d)
Application Manager - Cybersecurity, Compliance and Application Governance (m/f/d)

Siemens • Lisboa

Híbrido
EUR 60 000 - 90 000
Belong & Innovate
Hybrid model
Home office budget
+4
Cybersecurity Expert IT/OT (m/f/d)
Cybersecurity Expert IT/OT (m/f/d)

Siemens • Amadora

Presencial
EUR 70 000 - 110 000
Health insurance
On-site medical center
Volunteer days
+3
IT Operations Manager - English Speaker (m/f/d)
IT Operations Manager - English Speaker (m/f/d)

Siemens • Amadora

Híbrido
EUR 50 000 - 75 000
Hybrid model
Home office budget
Health insurance
+2
Senior SIEM Engineer
Senior SIEM Engineer

Claranet limited • Porto

Híbrido
EUR 60 000 - 90 000
Senior Backend Engineer (Research & Development) (m/f/d)
Senior Backend Engineer (Research & Development) (m/f/d)

Siemens • Amadora

Híbrido
EUR 80 000 - 110 000
Hybrid model
Flexible hours
Health insurance
+2
IT Server Administrator (m/f/d) at Siemens
IT Server Administrator (m/f/d) at Siemens

Siemens • Amadora

Híbrido
EUR 40 000 - 65 000
Hybrid model
Home office budget
Health insurance
+1