Senior SOC & SIEM Architect: Threat Detection & Response

Capgemini Engineering

Stockholms kommun

On-site

SEK 900,000 - 1,400,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Capgemini Engineering is looking for a Cybersecurity SOC/SIEM Architect to lead security monitoring and SOC operations across our environments in Sweden. You will design and optimize SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, ArcSight) and drive governance, detection use cases, and runbooks.

The ideal candidate combines deep SOC expertise with strong analytical and communication skills, enabling effective threat detection and incident response in a global, collaborative team.

Qualifications

  • Bachelor’s/master’s degree in Telecommunications, Electronics, or related field.
  • Minimum 8-10 years of experience in SOC, Cyber Defense Center, MSSP, or Security Operations environments.
  • Strong understanding of cybersecurity monitoring frameworks, operating models, and best practices.
  • Ability to bridge operational, architectural, and governance aspects of security monitoring and experience in documenting & formalizing security monitoring procedures & service workflows.
  • Excellent analytical, communication, and stakeholder management skills.
  • Fluency in English; Swedish language skills are advantageous.

Responsibilities

  • Leading and enhancing Security Operations Centre (SOC) capabilities, ensuring effective security monitoring, threat detection, incident analysis, and response activities.
  • Designing, implementing, and optimising SIEM platforms and security monitoring solutions, leveraging technologies such as Microsoft Sentinel, Splunk, QRadar, Elastic, ArcSight, or equivalent tools.
  • Defining and improving security monitoring operating models, governance frameworks, processes, procedures, and best practices required to deliver an effective SOC service.
  • Developing and maintaining detection use cases, correlation rules, alert workflows, monitoring KPIs, and continuous improvement initiatives to strengthen threat detection capabilities.
  • Establishing and managing security monitoring runbooks, incident handling procedures, threat hunting activities, and operational processes to support security operations.
  • Driving log management and event monitoring capabilities, including log collection, normalisation, enrichment, correlation, and integration across enterprise security and IT environments.

Skills

SOC operations
Security monitoring
Threat detection
SIEM knowledge
Cloud security

Education

Bachelor’s/Master’s degree in Telecommunications or Electronics

Tools

Microsoft Sentinel
Splunk
QRadar
Elastic (Elasticsearch)
ArcSight

Job description

Capgemini Engineering is looking for a Cybersecurity SOC/SIEM Architect to lead security monitoring and SOC operations across our environments in Sweden. You will design and optimize SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, ArcSight) and drive governance, detection use cases, and runbooks.

The ideal candidate combines deep SOC expertise with strong analytical and communication skills, enabling effective threat detection and incident response in a global, collaborative team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Architect
SOC Architect

Capgemini Engineering • Stockholms kommun

On-site
SEK 900,000 - 1,400,000
Senior Solution Architect - Detect & Respond Platforms
Senior Solution Architect - Detect & Respond Platforms

Sandvik Group • Stockholms kommun

Hybrid
SEK 900,000 - 1,200,000
Security Engineer: SIEM & Incident Response (Hybrid, Solna)
Security Engineer: SIEM & Incident Response (Hybrid, Solna)

PostNord Sverige • Solna kommun

Hybrid
SEK 750,000 - 950,000
Hybrid workplace
Great development opportunities
Insurance and pension terms
+2
Senior Cyber Security Specialist - SIEM & Incident Response
Senior Cyber Security Specialist - SIEM & Incident Response

Swediumglobal • Lunds kommun

On-site
SEK 660,000 - 881,000
Cyber Defense Lead: Incident Response & SOC Excellence
Cyber Defense Lead: Incident Response & SOC Excellence

Electrolux Group • Stockholms kommun

Hybrid
SEK 900,000 - 1,500,000
Hybrid work flexibility
Senior Security Operations Engineer — SIEM & Incident Response
Senior Security Operations Engineer — SIEM & Incident Response

Tandem Health • Stockholms kommun

On-site
SEK 900,000 - 1,200,000
Stock options
30 days paid holiday
Private medical insurance
+2
Cyber Security Specialist (Expert)
Cyber Security Specialist (Expert)

Swediumglobal • Lunds kommun

On-site
SEK 660,000 - 881,000
Azure Security Architect – Detect & Respond Platforms
Azure Security Architect – Detect & Respond Platforms

Sandvik AB • Stockholms kommun

Hybrid
SEK 1,200,000 - 1,600,000
Hybrid Security Engineer: SIEM & Threat Hunting
Hybrid Security Engineer: SIEM & Threat Hunting

PostNord • Solna kommun

Hybrid
SEK 650,000 - 850,000
Hybrid workplace
Great development opportunities
Insurance and occupational pension
+2
Senior Cyber Incident Response Analyst
Senior Cyber Incident Response Analyst

Integrity360 • Stockholms kommun

Hybrid
SEK 900,000 - 1,200,000