SIEM Engineer (Production Security)
Summary:
A leading international banking group is seeking a SIEM Engineering professional to strengthen its cyber threat detection and response capability. The role focuses on deploying, maintaining, and improving SIEM infrastructure, working closely with Production Infrastructure and Observability teams as a full-time member of the Production CSIRT/SIEM Engineering team.
Responsibilities:
- Install and administer SIEM infrastructure servers
- Develop automation for operational tasks and self-service tooling
- Support integration of new technology log sources
- Support log parsing using custom parsers/GROK development
- Contribute to project management activities
- Participate as a full-time member of the Production CSIRT/SIEM Engineering team
- Contribute to the Permanent Control framework (policies, procedures, control plans)
- Comply with regulatory requirements and internal guidelines
- Contribute to incident reporting per the Incident Management System
Qualifications/Requirements:
- 7+ years overall IT experience, with 4-5 years in a relevant SIEM/security engineering scope
- Mandatory: working knowledge of Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) — data ingestion, management, monitoring & analytics
- In-depth experience with Kafka
- Good working knowledge of Linux (RedHat/Ubuntu)
- Programming skills required: Python or Bash
- Experience as a production support engineer
- Platform integration experience (installation, configuration, documentation, administration across virtual and physical environments) is a plus
- Experience with automation tools (e.g., Ansible) and DevOps pipelines is a plus
- Strong problem-solving skills, ability to work autonomously, good interpersonal skills, high energy and ownership mindset
