We are looking for a SIEM Engineer, who will take full ownership of our security monitoring platform building, configuring, and optimizing Wazuh, managing log ingestion, creating and tuning detection rules. This role offers a unique opportunity to drive improvements in SIEM architecture, reduce false positives, and integrate new log sources, all while enhancing the organization’s overall security posture. The most important requirements are:
More than 3 years in the information security field.
Experience working with SIEM detections, log ingestion, log parsing, or operational monitoring
Job location — remotely
Core responsibilities: * Install, maintain, and upgrade Wazuh * Fix configuration issues, ingestion problems, agent issues * Create and tune detection rules and correlation logic * Normalize logs, map them to schemas, ensure consistent parsing * Integrate new log sources and build dashboards * Improve SIEM performance, scaling, storage, retention * Reduce noise and false positives * Maintain pipelines, decoders, and indexers * Take ownership of Wazuh architecture and drive continuous improvements
Core Technical Skills: * Hands-on experience with SIEM platforms, preferably including Wazuh, Splunk, or Microsoft Sentinel * Knowledge of endpoint security tools (EDR/XDR) * Understanding of network security (firewalls, IDS/IPS) * Basic scripting (Python, Bash, PowerShell) preferred
Complementary Expertise: * Experience with EDR, firewalls, IAM, vulnerability scanners * Experience improving broader security posture * Assist with technical investigations * Ability to implement security configurations across systems
Professional Skills: * Proficient English communication skills (reading, writing, speaking at B2 level or higher) * Ability to collaborate with cross-functional teams * Strong analytical and problem-solving skills
Education/Certifications: * Degree in Information Technology, Cybersecurity, or equivalent experience * One or more: Security+, CySA+, GCIH, or Microsoft Certified: Security Operations Analyst Associate, CASP/CISSP would be a plus but not required