About this role
The Position Join our team as a Senior SIEM Engineer for Cybersecurity Detection. As a member of the Cyber Intelligence & Security Operations Center (CISOC), you will play a key role in strengthening the organization's cyber defense capabilities through security monitoring, detection engineering, and automation. This role focuses on developing and enhancing SIEM/XDR use cases, improving detection effectiveness, integrating security technologies, and collaborating with cross-functional teams to proactively identify and mitigate security risks.
Duties and Responsibilities: Implement new security use cases on the SIEM/XDR. Use case fine-tuning to decrease the ratio of false positives. Implement new scripts and integrations to leverage and/or enrich SIEM/XDR technologies.
Maintenance of existing scripts and integrations. Support the implementation and maintenance of simulated threats to automatically test and enhance use cases. Evolve current technologies according to defined roadmap.
Collaboration on the improvement of the security detection capabilities with Security Detection and Incident Response team Act as point of contact for managing & delivering various reports & dashboards. Understand BI framework and follow defined processes. Ensure compliant documentation requirements and guarantee its production as required according to the SOPs and working instructions.
Work with various risk & information security teams in presenting security monitoring status & updates to technology subject matter experts & management. Abour our future employee: The ideal candidate will have a strong knowledge of: Proven experience in development of security use cases for SIEM/XDR technologies such as Splunk Enterprise Security, Microsoft Sentinel or Microsoft Defender. Certification is a plus.
Programming experience in scripting languages (Python, PowerShell, Bash) and API integration. Desired experience in BAS (breach & attack simulation) threat creation. Proven experience in reporting/ticketing platforms like ServiceNow.
Knowledge of common security weaknesses including remediation processes, prioritization, change management, analysis, & triage. Excellent spoken and written English. Experience working in a virtual, international and multicultural environment.
Analytical thinking, good communication, problem solving, results oriented, agility and teamwork skills. Security certifications like Security+ CE, GCIH, ECIH, OSCP, CEH are desired but not mandatory. Click here to know what it looks like working at Boehringer Ingelheim Business Services Philippines Inc.
