4 days ago
Vilnius, LithuaniaMid Level / Senior
Responsibilities
- Onboard endpoint, workstation, server, network, cloud-service, and SaaS logs into the centralized logging pipeline.
- Build and maintain parsers, normalization logic, data-routing and data-forking workflows for SIEM, data lake, and archival destinations.
- Operate and troubleshoot the Databahn, Cribl, or equivalent log-pipeline platform, including source health and ingestion failures.
- Ensure identity, endpoint, and behavioral telemetry is collected and enriched for UEBA and behavioral analytics.
- Build, tune, document, and maintain static, rule-based, dynamic, and behavioral detections through their full lifecycle.
- Create high-fidelity actionable alerts with production runbooks and maintain detection coverage against MITRE ATT&CK.
- Participate in detection simulations, adversary emulation, atomic testing, purple-team exercises, and false-positive reduction.
- Collaborate with SOC analysts and Threat Intelligence teams to turn triage feedback, TTPs, and IOCs into detection content.
- Build compliance and coverage dashboards and support audit, regulatory, M&A, and entity-onboarding activities.
- Participate in peer review, testing and CI for parser and detection changes, and support on-call or escalation rotations.
Requirements
- 4–6 years of experience in security engineering, SIEM engineering, detection/content engineering, or security data pipeline engineering.
- Hands-on Splunk engineering experience covering data onboarding, parsing, field extraction, source-type design, and SPL correlation searches.
- Practical experience with Databahn, Cribl, or a comparable log-pipeline and data-routing platform.
- Working understanding of MITRE ATT&CK and the ability to translate adversary techniques into detection logic.
- Working knowledge of endpoint, network, cloud, and identity/IAM telemetry and their implications for parsing and detection design.
- Scripting and automation experience using Python or a similar language for parser development, detection-as-code, testing, or enrichment.
- Experience with detection validation, atomic testing, or purple-team exercises.
- Experience integrating log data into a data lake or lakehouse platform and optimizing high-volume pipeline cost and volume.
- Exposure to UEBA, behavioral analytics, detection-as-code frameworks, Sigma, version-controlled repositories, and CI/CD for detection content.
- Experience with Splunk, ReliaQuest GreyMatter, or a comparable SIEM/AI SOC platform, plus compliance dashboards and M&A log-source integration.
- Relevant certifications such as Splunk Certified Admin/Architect, GCDA, GCIA, GCTI, or equivalent are preferred.
Benefits
- Full-time hybrid work arrangement in Lithuania.
- EUR 4,510–6,444 gross monthly salary.
- Competitive annual bonus and life insurance from Day 1.
- Best-in-class health insurance package and up to six fully paid benefit days per year.
- Referral bonus scheme, learning opportunities, and a global Employee Assistance Program.
- Office location in Quadrum with workplace amenities and fresh snacks.
