We are looking for an experienced SIEM specialist to perform advanced analysis of security events and incidents within a SIEM platform.
SIEM Specialist
Place of work
Banská Bystrica, partial home office possible (after the probation period and building mutual trust, partial work from home is possible).
Start date
ASAP
Salary conditions (gross)
EUR 2,000/mont
The actual base salary will be adjusted in line with your professional experience, knowledge and skills + 20% monthly KPI bonus after the probation period
Type of employment
Full-time employment
- Advanced analysis of security events and incidents within the SIEM platform
- Evaluation of correlations, alerts and anomalies across the infrastructure
- Independent handling of security incidents (L2), including the proposal of corrective measures
- Tuning of SIEM rules (reducing false positives, improving detection)
- Creation and maintenance of use-case scenarios and correlation rules
- Analysis of logs from various sources (OS, FW, IDS/IPS, EDR, applications, cloud)
- Escalation of incidents to the L3/IR team, including technical documentation
- Cooperation with IT, network and cloud teams in resolving security issues
- Preparation of analytical reports and recommendations for management
- Improvement of SOC processes, playbooks and incident response procedures
- Support and mentoring of L1 SOC Operators
Required education and experience:
- The position is suitable for candidates with the following education: secondary education with school-leaving exam, university degree (Bachelor’s), university degree (Master’s), in a technical IT field
- Advanced overview of IT security and cyber threats
- Practical experience with a SIEM platform (configuration, analysis, tuning)
- Knowledge of the following principles:
- Incident Response
- Event Management
- Threat Detection & Analysis
- Ability to analyse logs and network traffic
- Good knowledge of operating systems:
- Linux / Windows (processes, logs, service operation)
- Knowledge of network concepts:
- TCP/IP, DNS, HTTP(S), VPN, FW, NAT
- Experience with ITSM/ticketing tools and incident handling
- Ability to prepare technical documentation and communicate clearly in writing
- Language skills: English – Intermediate (B2), technical documentation and communication
- Years of experience: Minimum 4 years in IT
- Driving licence: Category B
Personal qualities and skills:
-
Responsibility and reliability
-
Independence
-
Precision and consistency
-
Experience with specific SIEM tools:
-
IBM QRadar
-
Wazuh
-
Splunk
-
Microsoft Sentinel
-
-
Experience with:
-
EDR/XDR solutions (Defender, CrowdStrike, SentinelOne)
-
IDS/IPS, firewalls (Palo Alto, FortiGate, Check Point)
-
-
Basic scripting knowledge:
-
Python, Bash, PowerShell (log analysis, automation)
-
-
Experience with cloud environments (Azure, AWS – security logs)
-
Knowledge of the MITRE ATT&CK framework
-
Awareness of compliance requirements (ISO 27001, NIS2, SOC2)
-
Flexibility and the ability to adapt to changes
-
Resistance to stress
-
Willingness to learn new things
What we offer:
- Opportunities for further education and career growth
- Self-realization
- Pleasant and modern working environment
- Free coffee, tea, beverages and fruit during working hours
- Possibility to work from home
- Participation in the supplementary pension savings scheme
- Sick days
- MultiSPORT card for sports and relaxation after work
- Company teambuilding event
We'd love to learn more about you. Do not hesitate to send your CV and cover letter to kariera@gamo.sk
Pursuant to Act No. 18/2018 Coll. on the protection of personal data, as amended, by submitting documents related to the selection procedure, the candidate gives consent to the management, processing and storage of personal data to GAMO a.s., with its registered office at Kyjevské nám. 6, Banská Bystrica, for the purpose of the selection procedure, for a period of 90 days. The job applicant may revoke this consent in writing at any time.
Do you have any questions about the position? Write and send them to us via the contact form, we will be happy to answer them.