Your area of work :
In your new position, you will become a member of the Cyber Defense team, part of Group Security. Cyber Defense team is responsible for all aspects of Security Information and Event Management (SIEM), Computer Emergency Response (CERT), and Security Operations Center (SOC).
In the advertised position, you will be focused on thecoordination with application teams to identify relevant log sources and ensure proper formatting, parsing, and secure transmission to the SIEM. You will also configure and validate log ingestion pipelines, including normalization, enrichment, and correlation rules to support threat detection and compliance use cases.
Your responsibilities :
- Engage with application owners to identify log sources, understand log formats, and define logging requirements aligned with security and compliance needs.
- Design and implement log ingestion workflows, including transport mechanisms (e.g., syslog, API, agent-based) and secure data handling practices.
- Configure parsing and normalization rules to ensure logs are structured correctly for correlation, alerting, and reporting within the SIEM.
- Validate log onboarding success by performing end-to-end testing, ensuring data completeness, accuracy, and timeliness.
- Maintain documentation for onboarded applications, including log source details, parsing logic, and use case mappings.
- Troubleshoot onboarding issues, offering suggestions for resolving parsing errors, ingestion delays, or misconfigured transport mechanisms.
- Collaborate with security teams to align log onboarding with detection use cases, compliance requirements, and threat intelligence integration.
Your profile :
University or comparable degree in Computer Science, Information Security, Engineering, or related discipline3+ years of experience working in the field of Cyber SecurityStrong understanding of SIEM platforms (Splunk, Microsoft Sentinel, QRadar, Google SecOps or similar) and log management principles.Experience working with log formats such as JSON, Syslog, CEF, and custom application logs.Familiarity with network and application architectures, including common protocols and security controls.Ability to collaborate with cross-functional teams, including application owners, infrastructure, and security operations.Proficient in scripting or automation tools (e.g., Python, PowerShell, Bash) to streamline onboarding and validation processes.Detail-oriented with strong analytical and troubleshooting skills to ensure data quality and support detection use cases.Excellent analytical skills, creativity, initiative, critical thinking, team player, ability to identify problems and propose solutionsProficiency in written and spoken English; French and / or German is an asset