17 sep
|
Next-link
|
San Cugat del Vallés
17 sep
Next-link
San Cugat del Vallés
At NextLink, we are looking for a Senior Security Engineer (SIEM) to join our team and collaborate closely with one of our most recognized clients in the pharmaceutical sector.
You will join the Cyber Intelligence & Security Operations Center (CISOC) team, focusing on security monitoring and detection capabilities through SIEM/XDR technologies.
The role combines hands-on security engineering, use case development, automation, detection improvement, reporting, and collaboration with Security Detection, Incident Response, Risk, and Information Security teams.
Main Responsibilities
- Design, implement, and continuously improve SIEM/XDR security use cases, including fine-tuning to reduce false positives.
- Develop and maintain scripts, integrations, and APIs to enrich SIEM/XDR capabilities and automate security monitoring activities.
- Support the implementation and maintenance of simulated threats / BAS scenarios to test and improve detection use cases.
- Contribute to the evolution of security technologies in line with the defined roadmap and improve detection capabilities together with Security Detection and Incident Response teams.
- Act as a point of contact for security monitoring reports and dashboards, presenting status and updates to technical experts and management.
- Follow defined frameworks, processes, SOPs, and working instructions, ensuring compliant and up-to-date documentation.
- Collaborate with Risk and Information Security teams on identified risks, remediation, prioritisation, analysis, triage, and security monitoring improvements.
Requirements
- Proven hands-on experience with SIEM/XDR technologies and security monitoring/detection activities.
- Experience developing and fine-tuning security detection use cases, ideally with technologies such as Microsoft Sentinel or Microsoft Defender.
- Programming/scripting experience with Python, PowerShell, Bash, or similar, including API integrations.
- Good understanding of security weaknesses, remediation processes, prioritization, change management, analysis, and triage.
- Strong analytical thinking, problem-solving, communication, teamwork, agility, and results-oriented skills.
- Excellent spoken and written English.
- Experience working in virtual, international, and multicultural environments.
Desirable Requirements
- Experience with Breach & Attack Simulation (BAS) and simulated threat creation.
- Experience with reporting and ticketing platforms such as ServiceNow.
- Relevant SIEM/XDR certifications, particularly related to Microsoft Sentinel or Microsoft Defender, are a plus.
- Security certifications such as Security+, CE, GCIH, ECIH, OSCP, or CEH are desirable but not mandatory.
📌 Senior Security Engineer (SIEM) (San Cugat del Vallés)
🏢 Next-link
📍 San Cugat del Vallés