Jobs Companies Cencora Senior Information Security Engineer

About this Senior Information Security Engineer role at Cencora

Cencora · Onsite · Vilnius, Lithuania

Cencora, previously known as AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving lives. Ranked #21 on the Global Fortune 500, our team members are united in our responsibility to create healthier futures.

Our Shared Service Center in Lithuania is experiencing rapid growth and we have many diverse and exciting roles in Customer Service, Operations, IT, Finance and HR.  Join us and make a positive impact on human and animal health.

Job Details

Hands-on engineering role spanning the security data pipeline and the detection content it powers. Onboards, parses, normalizes, and routes log and telemetry data into the SIEM and data lake, and builds and tunes the detections that turn that telemetry into high-fidelity, actionable alerts. This is a full individual-contributor role for an engineer who wants ownership of the end-to-end path from raw log source to validated detection, without the artificial handoff between "data" and "detection" work. Reports to Principal Engineer or Head of Cyber Defense Engineering. Individual contributor - no direct reports. Expected to work independently on assigned domains and to guide less experienced engineers informally through peer review and pairing. 

Responsibilities:

Data Pipeline & Telemetry

  • Onboard security and operational log sources - endpoints, workstations, servers, network devices, cloud services, and SaaS - into the centralized logging pipeline. 

  • Build and maintain parsers and normalization logic to ensure schema consistency and field-level usability for downstream detection and correlation. 

  • Implement and maintain data forking/routing logic to multiple destinations, including SIEM, data lake, and archival storage. 

  • Apply categorization logic that separates security-relevant from operational data, tuning cost and signal-to-noise across destinations. 

  • Operate day-to-day on the data pipeline platform (Databahn, Cribl, or equivalent), including source health monitoring and troubleshooting ingestion failures. 

  • Ensure the identity, endpoint, and behavioral data required for UEBA and behavioral analytics is collected, enriched, and available. 

  • Build and maintain compliance and coverage dashboards and reporting from log data to support audit and regulatory requests. 

  • Contribute to log-source integration for M&A and entity-onboarding activity under the direction of a lead. 

Detection Engineering 

  • Build and maintain detections - both static/rule-based and dynamic/behavioral - covering malicious and anomalous activity across the environment. 

  • Own assigned detection content through its lifecycle: continuously tune existing rules and develop new use cases as adversary TTPs evolve. 

  • Ensure alerts are high-fidelity, actionable, and mapped to real risk, with a documented runbook accompanying every production detection. 

  • Participate in detection simulations and adversary emulation exercises (MITRE ATT&CK based) to validate coverage and drive down false positives. 

  • Work directly with SOC Analysts on the triage feedback loop, and with Threat Intelligence on emerging TTPs and IOCs, converting both into detection content. 

  • Maintain the detection coverage map against MITRE ATT&CK for assigned domains and surface gaps, including gaps caused by missing telemetry. 

  • Follow and help improve detection engineering standards: documentation, version control, peer review, and testing/CI for detection content. 

Cross-Cutting 

  • Close the loop between the two domains: translate detection data gaps into pipeline onboarding or parsing work, and validate that newly onboarded data is fit for detection purposes. 

  • Participate in peer review of both parser/pipeline changes and detection content. 

  • Support on-call or escalation rotation for pipeline and detection platform issues as required. 

Work Experience:

  • 4-6 years in security engineering, SIEM engineering, detection/content engineering, or security data pipeline engineering, with demonstrable hands-on delivery in at least one of the two domains and working capability in the other. 

  • Hands-on Splunk engineering experience covering both sides: data onboarding, parsing/field extraction, and source-type design, plus writing and tuning SPL correlation searches. 

  • Practical experience with a log pipeline/data routing platform (Databahn, Cribl, or comparable) for ingestion, parsing, normalization, and multi-destination routing. 

  • Working understanding of MITRE ATT&CK and the ability to translate adversary techniques into detection logic. 

  • Working knowledge of endpoint, network, cloud, and identity/IAM telemetry - both the parsing challenges each presents and how each informs detection design. 

  • Scripting and automation skills (Python or similar) applied to parser development, detection-as-code, testing, or enrichment. 

  • Experience contributing to detection validation, atomic testing, or purple-team exercises. 

Preferred Certifications:

  • Relevant certifications (Splunk Certified Admin/Architect, GCDA, GCIA, GCTI, or equivalent). 

Skills and Knowledge:

  • Experience integrating log data into a data lake/lakehouse platform for large-scale storage and analytics. 

  • Exposure to UEBA-driven and behavioral analytics, not only signature-based detection. 

  • Familiarity with detection-as-code frameworks (Sigma, version-controlled detection repos, CI/CD for content). 

  • Familiarity with cost/volume optimization for high-volume log pipelines (filtering, sampling, tiered storage). 

  • Experience with Splunk/ReliaQuest GreyMatter or a comparable SIEM/AI SOC platform. 

  • Experience supporting log-source integration during M&A or entity onboarding. 

  • Experience building compliance dashboards and reporting from log data. 

Salary: 4510 - 6444 EUR gross monthly

# Li-hybrid

What Cencora offers

We offer a competitive annual bonus, life insurance from Day 1, a best-in-class health insurance package, and up to 6 fully paid benefit days a year. As a Cencora employee, you have the benefit of our referral bonus scheme, our boundless learning opportunities and our global Employee Assistance Program. We have a wonderful office location in Quadrum, equipped with everything you need for a small break at work and fresh snacks at all times. Become part of our purpose-driven, multicultural team now and help us create healthier futures

Full time

Affiliated Companies:

Affiliated Companies: World Courier (Lithuania) UAB

Ready to apply to Cencora?
Apply to Cencora

About Cencora

Recruitment scams are on the rise and the intent is to target individuals looking for employment opportunities. To protect yourself, we urge you to be vigilant and follow these guidelines. ​1.) Research the Company: Thoroughly research any company before applying or sharing personal information, check their website, read reviews, and verify their legitimacy. 2.) Be Wary of Unrealistic Promises: Exercise caution If a job posting offers high salaries and minimal qualifications. Legitimate jobs will have realistic expectations and provide detailed job requirements. Jobs at Cencora can be found on Cencora.com/careers 3.) Guard Your Personal Information: Only share sensitive information after vet

See all jobs at Cencora →

Similar jobs

Lloyds Banking Group
WAF Security Engineer
Lloyds Banking Group
⚡ Apply early Manchester Onsite £48,987–£55,000
● New 👁 Seen ✓ Applied 2h ago
HP
Cybersecurity Threat Detection & Response Engineer
HP
⚡ Apply early Sant Cugat del Valles, Barcelo... Onsite
● New 👁 Seen ✓ Applied 2h ago
HP
Systems Infrastructure & Network Security Operations Engineer
HP
⚡ Apply early Spring, Texas, United States o... Onsite $93,400–$143,800
● New 👁 Seen ✓ Applied 2h ago
HP
Software Product Security Engineer Intern
HP
⚡ Apply early Spring, Texas, United States o... Onsite $72,800–$83,200
● New 👁 Seen ✓ Applied 2h ago
Vertex Inc
Security Operations Engineer
Vertex Inc
⚡ Apply early Remote USA · location restricted $91,200–$118,600
● New 👁 Seen ✓ Applied 5h ago
Vertex Inc
Senior AI Security Engineer
Vertex Inc
⚡ Apply early Remote USA · location restricted $120,700–$156,900
● New 👁 Seen ✓ Applied 5h ago
MA
Oliver Wyman Vector - DevOps Engineer (AWS & Cybersecurity)
Marsh
⚡ Apply early Atlanta - Hartsfield Onsite $90,000–$115,000
● New 👁 Seen ✓ Applied 6h ago
Anduril Industries
Senior Product Security Engineer
Anduril Industries
⚡ Apply early Fort Collins, Colorado, United... Onsite $144,000–$191,000
● New 👁 Seen ✓ Applied 11h ago
Gong.io
Senior Cloud Security Engineer
Gong.io
⚡ Apply early Tel Aviv Onsite
● New 👁 Seen ✓ Applied 11h ago

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Cencora

See all jobs at Cencora →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free