Senior SIEM Engineer
Expleo Group
Remoto
We are strategically positioned to build value, with global footprint across 30 countries.
We are as global and local as you need us to be, with strong best-in-class pan-European technological centres and unique best-shoring capabilities.
We leverage a network of high value-adding affiliates in consulting and industrial excellence, and leading partners across multiple sectors to provide you with the most comprehensive services and solutions in an ever-changing environment.
Responsibilities
- Administration, implementation, and optimization of Microsoft Sentinel environments.
- Development and optimization of detection rules and KQL queries.
- Integration and management of log sources and security telemetry.
- Hands-on experience with Graylog, Logstash, Syslog-ng, NXLog, Windows Event Forwarding (WEF), and Syslog.
- Automation using PowerShell, Bash, Python, and/or Ansible.
- Management of Linux environments and security infrastructure.
- Experience with Docker/Podman and containerized environments.
- Improving monitoring coverage and reducing false positives.
- Collaboration with infrastructure, network, and security teams.
- Production and maintenance of technical documentation and operational procedures.