Description
Andersen is hiring a SIEM Administrator / Engineer for a project enhancing a SIEM platform and supporting centralized security monitoring and threat detection.
Our customer is a technology and consulting organization providing digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support.
It helps organizations modernize complex technology environments, strengthen security, and improve the reliability and scalability of their digital operations.
By combining technical expertise with modern technologies and service-oriented delivery, the company supports digital transformation, operational efficiency, and the continuous improvement of critical IT systems across multiple markets.
The project is focused on providing cybersecurity and digital services for international organizations within a complex multi-tenant environment.
It includes managing and enhancing the SIEM platform to support centralized security monitoring, threat detection, and reliable cyber defense operations across multiple organizations worldwide.
Responsibilities:
Administering, maintaining and upgrading the SIEM platform, including health, performance, capacity and licensing.
Onboarding and normalizing new log sources (network, endpoint, cloud, identity, applications), including in multi-tenant setups.
Developing, tuning and maintaining detection rules, correlation searches, dashboards and reports.
Reducing false positives together with SOC analysts and implementing new use cases.
Building and maintaining SOAR playbooks and integrations.
Maintaining documentation, data retention policies and access control.
Supporting audits and compliance reporting.
Requirements:
Experience in IT or cybersecurity for 5+ years, including 3+ years administering an enterprise SIEM in production.
Deep hands-on experience with at least one major SIEM: Microsoft Sentinel, Splunk ES, IBM QRadar or Elastic Security.
Hands-on experience with log source onboarding, parsing, and normalization using Syslog, CEF, Windows Event Forwarding (WEF), and API-based cloud connectors.
Experience writing detection content in the platform's query language (KQL, SPL, AQL or equivalent).
Understanding of MITRE ATT&CK for mapping detection coverage.
Clean professional records and willingness to undergo background verification.
Level of English – from Upper-Intermediate and above.
Nice-to-haves:
Vendor certifications (e.g.
Microsoft SC-200, Splunk Certified Admin/Architect, IBM QRadar).
SOAR experience (Sentinel Logic Apps, Splunk SOAR, Cortex XSOAR).
Multi-tenant SIEM or MSSP experience.
Experience in scripting and automation (Python, PowerShell) and Infrastructure as Code.
Experience working with detection-as-code practices (Sigma, Git-based rule management).
Reasons why this job would be interesting to you:
Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others.
Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
The opportunity to change the project and/or develop expertise in an interesting business domain.
Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).
Certification compensation (AWS, PMP, etc).
Referral program.
Private health insurance and sports compensation, depending on the type of employment.
Your personal data is protected in accordance with GDPR regulations.
Learn more: https://andersenlab.com/privacy-policy/pl
Join us!