IT SIEM Engineer
Indexed description
Who we are
SII Group is a trusted technology partner, SII provides high value added solutions for the IT projects of many large corporations. Since its founding in 1979, the Company has been providing solutions adapted to its clients’ needs, by relying on :
> Its acknowledged expertise in various industries and sectors
> Proven 'turnkey' solutions
> An efficient quality system
> Adaptable, evolving services
Today, with a staff of more than 18'000, SII Group is supporting companies across 20 countries.
At SII Switzerland we pay attention to the personal and professional wellbeing of our employees. We place our collaborators at the heart of our actions and activities. If you are motivated by the perspective of joining a big, trusted and recognized group, then let's meet !
To develop our consulting offer and support one of our clients, we are looking for a talented IT SIEM Engineer.
Missions
- Engineer, configure, maintain, and monitor the SIEM platform, collectors, connectors, and supporting infrastructure.
- Onboard security-relevant logs from identity, endpoint, network, cloud, business applications, databases, and other environments.
- Design reliable data pipelines; develop parsing, normalization, transformation, timestamp handling, and contextual enrichment.
- Monitor telemetry health and resolve missing sources, ingestion delays, volume anomalies, schema changes, and connector failures.
- Support detection engineering with required fields, correlation logic, threat intelligence, MITRE ATT&CK mapping, and testing.
- Optimize ingestion, storage tiers, retention, query performance, licensing, and cost without reducing required security visibility.
- Maintain architecture diagrams, log-source inventory, onboarding standards, runbooks, ownership, and configuration records.
- Support SOC investigations, threat hunting, incident response, forensic data extraction, audits, and major incident resolution.
- Coordinate logging requirements and remediation with IT, Cloud, Network, IAM, Application, OT, vendors, and service providers.
Profile
- Practical experience in SIEM engineering, security monitoring, log management, or security platform engineering.
- Hands-on experience with enterprise SIEMs, preferably Microsoft Sentinel; Splunk, QRadar, Elastic, or Google SecOps also relevant.
- Experience onboarding and troubleshooting logs across Windows, Linux, Entra ID, cloud, network, endpoint, and application environments.
- Proficiency in KQL, SPL, SQL, or similar query languages, with analytics and performance troubleshooting.
- Knowledge of syslog, APIs, agents, collectors, event streaming, parsing, normalization, and enrichment.
- Scripting/automation skills with PowerShell, Python, REST APIs, Git, CI/CD, or IaC.
- Understanding of detection engineering, incident response, forensics, networking, security controls, and data protection.
- Strong analytical, documentation, communication, and ownership skills; professional English required.
- Knowledge of SIEM/data lake architecture, SOAR, detection-as-code, and regulated/critical infrastructure or OT environments.
- Familiarity with NIS2, ISO 27001, IEC 62443, log retention requirements, and relevant security certifications.
For information
- Start date: ASAP
- Location: remote from Switzerland
- Languages: Fluent English, German is a plus
- Requirement: European citizen
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search