This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Our team is looking for a motivated and experienced SIEM/SOC Leader (Security information and event management) in Athens to support our client on a European institution project. As a SIEM/SOC Leader, you will own the end-to-end SIEM service, ensuring effective log onboarding, detection engineering, and operational support for Security Operations (SOC). You will be responsible for improving detection coverage, alert quality, and response enablement, while ensuring the SIEM platform operates reliably and delivers measurable security outcomes.
Job Responsibility:
Own and manage the end-to-end SIEM service, including onboarding of log sources, detection use cases, and continuous improvements.
Define and maintain the SIEM operating model, backlog, priorities, and delivery roadmap.
Ensure SIEM platform health (log ingestion, parsing, normalization, storage, performance, retention, and capacity).
Manage integrations (log collectors, APIs, cloud connectors) and oversee upgrades and maintenance.
Develop and maintain detection rules, correlation logic, dashboards, and analytics.
Govern the full detection lifecycle (design, build, test, deploy, tune, retire).
Improve detection quality by reducing false positives and enhancing alert accuracy.
Integrate and operationalize threat intelligence (IoCs, TTPs) and enrich detections with contextual data.
Ensure alerts are actionable, with clear triage guidance, severity levels, and response playbooks.
Collaborate with SOC and Incident Response teams on incident handling, escalations, and post-incident improvements.
Drive automation and orchestration (e.g., SOAR integrations) to improve efficiency and response times.
Requirements:
Bachelor in Engineer in Computer Science or equivalent.
Minimum 8 years of experience in the field.
Strong hands-on experience with SIEM platforms (engineering, operations, and use-case development).
Solid understanding of log management, including ingestion, parsing, normalization, and correlation.
Experience with common log sources (OS, network, IAM, endpoint, cloud, and application logs).
Knowledge of detection engineering, SOC operations, and incident triage processes.
Familiarity with threat intelligence and enrichment techniques.
Experience with scripting and automation (e.g., Python) and API integrations.
Working knowledge of query languages such as KQL, SPL, or SQL-like.
Understanding of ITIL-based service management (incident, problem, change processes).
What we offer:
Health insurance for the employee and one dependent family member (100% paid by NTT DATA)
Meal vouchers of 120€ per month (x12)
Corporate mobile phone: subscription & device
Teleworking equipment allowance
Udemy Account
Access to Open Up mental health service
28 days of paid annual leave consisting of your legal holidays and compensation days