SOC Architect

Capgemini Engineering

Stockholms kommun

On-site

SEK 900,000 - 1,400,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Capgemini Engineering is looking for a Cybersecurity SOC/SIEM Architect to lead security monitoring and SOC operations across our environments in Sweden. You will design and optimize SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, ArcSight) and drive governance, detection use cases, and runbooks.

The ideal candidate combines deep SOC expertise with strong analytical and communication skills, enabling effective threat detection and incident response in a global, collaborative team.

Qualifications

  • Bachelor’s/master’s degree in Telecommunications, Electronics, or related field.
  • Minimum 8-10 years of experience in SOC, Cyber Defense Center, MSSP, or Security Operations environments.
  • Strong understanding of cybersecurity monitoring frameworks, operating models, and best practices.
  • Ability to bridge operational, architectural, and governance aspects of security monitoring and experience in documenting & formalizing security monitoring procedures & service workflows.
  • Excellent analytical, communication, and stakeholder management skills.
  • Fluency in English; Swedish language skills are advantageous.

Responsibilities

  • Leading and enhancing Security Operations Centre (SOC) capabilities, ensuring effective security monitoring, threat detection, incident analysis, and response activities.
  • Designing, implementing, and optimising SIEM platforms and security monitoring solutions, leveraging technologies such as Microsoft Sentinel, Splunk, QRadar, Elastic, ArcSight, or equivalent tools.
  • Defining and improving security monitoring operating models, governance frameworks, processes, procedures, and best practices required to deliver an effective SOC service.
  • Developing and maintaining detection use cases, correlation rules, alert workflows, monitoring KPIs, and continuous improvement initiatives to strengthen threat detection capabilities.
  • Establishing and managing security monitoring runbooks, incident handling procedures, threat hunting activities, and operational processes to support security operations.
  • Driving log management and event monitoring capabilities, including log collection, normalisation, enrichment, correlation, and integration across enterprise security and IT environments.

Skills

SOC operations
Security monitoring
Threat detection
SIEM knowledge
Cloud security

Education

Bachelor’s/Master’s degree in Telecommunications or Electronics

Tools

Microsoft Sentinel
Splunk
QRadar
Elastic (Elasticsearch)
ArcSight

Job description

At Capgemini Engineering, the world leader in engineering services, we bring together a global team of engineers, scientists, and architects to help the world’s mostinnovative companies unleash their potential. From autonomous cars to life‑saving robots, our digital and software technology experts think outside the box as theyprovide unique R&D and engineering services across all industries. Join us for a career full of opportunities. Where you can make a difference. Where no two days arethe same.

Your role

As a Cybersecurity SOC/SIEM Architect, you will be responsible for security monitoring, SOC operations, and SIEM-related activities across the environment. The ideal candidate will possess strong expertise in SOC and SIEM ecosystems, security monitoring technologies, and cyber threat detection and response. Most importantly, the candidate should have a solid understanding of the operational processes, procedures, governance frameworks, and best practices required to establish and maintain an effective security monitoring capability.

In this role you will play a key role in:
  • Leading and enhancing Security Operations Centre (SOC) capabilities, ensuring effective security monitoring, threat detection, incident analysis, and response activities.
  • Designing, implementing, and optimising SIEM platforms and security monitoring solutions, leveraging technologies such as Microsoft Sentinel, Splunk, QRadar, Elastic, ArcSight, or equivalent tools.
  • Defining and improving security monitoring operating models, governance frameworks, processes, procedures, and best practices required to deliver an effective SOC service.
  • Developing and maintaining detection use cases, correlation rules, alert workflows, monitoring KPIs, and continuous improvement initiatives to strengthen threat detection capabilities.
  • Establishing and managing security monitoring runbooks, incident handling procedures, threat hunting activities, and operational processes to support security operations.
  • Driving log management and event monitoring capabilities, including log collection, normalisation, enrichment, correlation, and integration across enterprise security and IT environments.
Your profile
  • Bachelor’s/master’s degree in Telecommunications, Electronics, or related field
  • Minimum 8-10 years of experience in SOC, Cyber Defense Center, Managed Security Services (MSSP), or Security Operations environments.
  • Strong understanding of cybersecurity monitoring frameworks, operating models, and best practices.
  • Ability to bridge operational, architectural, and governance aspects of security monitoring and experience in documenting & formalizing security monitoring procedures & service workflows.
  • Excellent analytical, communication, and stakeholder management skills.
  • Fluency in English; Swedish language skills are advantageous.
What We Believe You Will Enjoy About Working Here
  • Working with cutting‑edge telecom technologies, including 5G Core and cloud‑native architectures.
  • Opportunities to contribute to large‑scale transformation projects for leading telecom clients.
  • Being part of a collaborative, international, and highly skilled team.
  • Continuous learning opportunities and strong career development support.
Application

As part of our recruitment process, identity verification will be conducted through inspection of your ID card, and background checks may be carried out as required.

About Capgemini

Capgemini is an AI‑powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology, and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end‑to‑end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion. Make it real | www.capgemini.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC & SIEM Architect: Threat Detection & Response
Senior SOC & SIEM Architect: Threat Detection & Response

Capgemini Engineering • Stockholms kommun

On-site
SEK 900,000 - 1,400,000
System Engineer
System Engineer

Capgemini Engineering • Göteborgs kommun

Hybrid
SEK 700,000 - 1,100,000
Flexible work arrangements
Career growth programs
Education library with 250,000 courses
Test Specialist (OSS, NOC, SOC)
Test Specialist (OSS, NOC, SOC)

Capgemini Engineering • Stockholms kommun

On-site
SEK 900,000 - 1,200,000
Digital Trust and Cyber Security Management Consultant
Digital Trust and Cyber Security Management Consultant

Capgemini AB • Stockholms kommun

On-site
SEK 638,000 - 851,000
Impactful work
Access to training and mentorship
Collaborative culture
+1
NOC SOC Exploitability Solution Architect
NOC SOC Exploitability Solution Architect

Capgemini AB • Stockholms kommun

Hybrid
SEK 700,000 - 900,000
Flexible work arrangements
Structured career development programs
Access to an education library
Cybersecurity Testing & Operations Specialist
Cybersecurity Testing & Operations Specialist

Capgemini Engineering • Stockholms kommun

On-site
SEK 900,000 - 1,200,000
Cyber Defence Expert - Incident Management & Response
Cyber Defence Expert - Incident Management & Response

Electrolux Group • Stockholms kommun

Hybrid
SEK 900,000 - 1,500,000
Hybrid work flexibility
Security Analyst specializing in Operational Technology (OT)
Security Analyst specializing in Operational Technology (OT)

Orange Cyberdefense Sweden AB • Stockholms kommun

On-site
SEK 550,000 - 750,000
SOC Analyst
SOC Analyst

Telia Sverige AB • Göteborgs kommun

Hybrid
SEK 497,000 - 720,000
Comprehensive benefits package
Opportunities for remote work
Performance-based bonus
Security Analyst specializing in Operational Technology (OT)
Security Analyst specializing in Operational Technology (OT)

Orange Cyberdefense • Sweden

On-site
SEK 650,000 - 950,000