onsite
Senior Security Engineer - Splunk, Cribl & Azure Sentinel - Help AG
Security Engineer
Senior Security Engineer leading the design, deployment, and maintenance of Splunk, Cribl, Azure Sentinel, and EDR solutions to protect client and internal environments, driving threat analysis and process automation.
About the role
Key Responsibilities
- Design, implement, and maintain Splunk, Cribl, Azure Sentinel, and EDR platforms for real‑time threat detection and incident response.
- Develop and refine security procedures, playbooks, and automation scripts to streamline operations and reduce mean time to detect.
- Collaborate with Threat Analysts, Solution Architects, and senior engineers to conduct security assessments, vulnerability scans, and penetration tests.
- Provide expert guidance to Managed Security Service clients on platform configuration, tuning, and best practices.
- Lead incident investigations, root cause analysis, and post‑mortem reporting to improve security posture.
Requirements
- 5+ years of experience in security engineering with hands‑on Splunk, Cribl, Azure Sentinel, and EDR deployments.
- Strong knowledge of SIEM, SOAR, and log management concepts, including data ingestion, correlation, and alerting.
- Proficiency in scripting (Python, PowerShell, Bash) for automation and data manipulation.
- Experience with threat intelligence feeds, incident response frameworks, and compliance standards (PCI, HIPAA, NIST).
- Excellent communication skills and ability to work cross‑functionally with technical and non‑technical stakeholders.