Security Operations Center - SIEM Architect
Job TitleSecurity Operations Center - SIEM ArchitectJob DescriptionIntroduction Vanderlande’s Security Operations Center (SOC) is looking for a SIEM Engineer with experience designing, operating, and optimizing enterprise security monitoring platforms. Skilled in log ingestion, detection engineering, alert tuning, and dashboard development to support SOC operations, incident response, and compliance requirements. What will you be doing? Onboards log sources (Windows, Linux, firewalls, cloud, SaaS apps) Parses and normalizes logs so data is searchable and consistent Creates detection rules and alerts for threats (e.g., brute force, malware, insider risk) Tunes alerts to reduce false positives Builds dashboards and reports for SOC teams and leadership Maintains performance and reliability of the SIEM Supports incident response by helping analysts investigate alerts Ensures compliance (e.g., log retention for ,NIS2, ISO 27001, IEC62443) What are your responsibilities?Engineered and maintained multitenant SIEM platforms (, supporting enterprise‑scale security monitoring Onboarded and normalized logs from servers, endpoints, network devices, cloud services, and security tools (EDR, IAM, IDS firewalls) Developed and tuned correlation rules, detections, and alerts, reducing false positives and improving threat detection accuracy Mapped detections to the MITRE ATT&CK framework to strengthen coverage of adversary techniques Built operational and executive dashboards to improve SOC visibility and reporting Integrated threat intelligence feeds to enhance detection capabilities Supported SOC analysts during investigations by providing log analysis and forensic context Automated SIEM tasks and data processing using Python, PowerShell, and Bash Optimized log retention and storage to balance performance, cost, and regulatory requirements Documented SIEM architecture, detections, and onboarding processes for audit readiness What do we ask from you?Desired Technical Skills SIEM Platforms: e.g. Splunk, Microsoft Sentinel Exabeam Elastic Log Sources: Windows Event Logs, Linux Syslog, Firewall, Proxy, IAM, EDR Cloud Logging: Azure Monitor, AWS CloudTrail, GCP Logging Security Frameworks: MITRE ATT&CK, NIST, Incident Response Lifecycle Scripting & Automation: Python, PowerShell, Bash Networking: TCP/IP, DNS, HTTP/S Other Skills Strong analytical and problem‑solving skills Ability to communicate technical issues to non‑technical stakeholders Attention to detail and documentation Ability to work independently and collaboratively Experience 4+ years in cybe...