Jobs Companies Cencora Senior Information Security Engineer

À propos de ce poste Senior Information Security Engineer chez Cencora

Cencora · Sur site · Vilnius, Lithuania

Cencora, previously known as AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving lives. Ranked #21 on the Global Fortune 500, our team members are united in our responsibility to create healthier futures.

Our Shared Service Center in Lithuania is experiencing rapid growth and we have many diverse and exciting roles in Customer Service, Operations, IT, Finance and HR.  Join us and make a positive impact on human and animal health.

Job Details

Hands-on engineering role spanning the security data pipeline and the detection content it powers. Onboards, parses, normalizes, and routes log and telemetry data into the SIEM and data lake, and builds and tunes the detections that turn that telemetry into high-fidelity, actionable alerts. This is a full individual-contributor role for an engineer who wants ownership of the end-to-end path from raw log source to validated detection, without the artificial handoff between "data" and "detection" work. Reports to Principal Engineer or Head of Cyber Defense Engineering. Individual contributor - no direct reports. Expected to work independently on assigned domains and to guide less experienced engineers informally through peer review and pairing. 

Responsibilities:

Data Pipeline & Telemetry

  • Onboard security and operational log sources - endpoints, workstations, servers, network devices, cloud services, and SaaS - into the centralized logging pipeline. 

  • Build and maintain parsers and normalization logic to ensure schema consistency and field-level usability for downstream detection and correlation. 

  • Implement and maintain data forking/routing logic to multiple destinations, including SIEM, data lake, and archival storage. 

  • Apply categorization logic that separates security-relevant from operational data, tuning cost and signal-to-noise across destinations. 

  • Operate day-to-day on the data pipeline platform (Databahn, Cribl, or equivalent), including source health monitoring and troubleshooting ingestion failures. 

  • Ensure the identity, endpoint, and behavioral data required for UEBA and behavioral analytics is collected, enriched, and available. 

  • Build and maintain compliance and coverage dashboards and reporting from log data to support audit and regulatory requests. 

  • Contribute to log-source integration for M&A and entity-onboarding activity under the direction of a lead. 

Detection Engineering 

  • Build and maintain detections - both static/rule-based and dynamic/behavioral - covering malicious and anomalous activity across the environment. 

  • Own assigned detection content through its lifecycle: continuously tune existing rules and develop new use cases as adversary TTPs evolve. 

  • Ensure alerts are high-fidelity, actionable, and mapped to real risk, with a documented runbook accompanying every production detection. 

  • Participate in detection simulations and adversary emulation exercises (MITRE ATT&CK based) to validate coverage and drive down false positives. 

  • Work directly with SOC Analysts on the triage feedback loop, and with Threat Intelligence on emerging TTPs and IOCs, converting both into detection content. 

  • Maintain the detection coverage map against MITRE ATT&CK for assigned domains and surface gaps, including gaps caused by missing telemetry. 

  • Follow and help improve detection engineering standards: documentation, version control, peer review, and testing/CI for detection content. 

Cross-Cutting 

  • Close the loop between the two domains: translate detection data gaps into pipeline onboarding or parsing work, and validate that newly onboarded data is fit for detection purposes. 

  • Participate in peer review of both parser/pipeline changes and detection content. 

  • Support on-call or escalation rotation for pipeline and detection platform issues as required. 

Work Experience:

  • 4-6 years in security engineering, SIEM engineering, detection/content engineering, or security data pipeline engineering, with demonstrable hands-on delivery in at least one of the two domains and working capability in the other. 

  • Hands-on Splunk engineering experience covering both sides: data onboarding, parsing/field extraction, and source-type design, plus writing and tuning SPL correlation searches. 

  • Practical experience with a log pipeline/data routing platform (Databahn, Cribl, or comparable) for ingestion, parsing, normalization, and multi-destination routing. 

  • Working understanding of MITRE ATT&CK and the ability to translate adversary techniques into detection logic. 

  • Working knowledge of endpoint, network, cloud, and identity/IAM telemetry - both the parsing challenges each presents and how each informs detection design. 

  • Scripting and automation skills (Python or similar) applied to parser development, detection-as-code, testing, or enrichment. 

  • Experience contributing to detection validation, atomic testing, or purple-team exercises. 

Preferred Certifications:

  • Relevant certifications (Splunk Certified Admin/Architect, GCDA, GCIA, GCTI, or equivalent). 

Skills and Knowledge:

  • Experience integrating log data into a data lake/lakehouse platform for large-scale storage and analytics. 

  • Exposure to UEBA-driven and behavioral analytics, not only signature-based detection. 

  • Familiarity with detection-as-code frameworks (Sigma, version-controlled detection repos, CI/CD for content). 

  • Familiarity with cost/volume optimization for high-volume log pipelines (filtering, sampling, tiered storage). 

  • Experience with Splunk/ReliaQuest GreyMatter or a comparable SIEM/AI SOC platform. 

  • Experience supporting log-source integration during M&A or entity onboarding. 

  • Experience building compliance dashboards and reporting from log data. 

Salary: 4510 - 6444 EUR gross monthly

# Li-hybrid

What Cencora offers

We offer a competitive annual bonus, life insurance from Day 1, a best-in-class health insurance package, and up to 6 fully paid benefit days a year. As a Cencora employee, you have the benefit of our referral bonus scheme, our boundless learning opportunities and our global Employee Assistance Program. We have a wonderful office location in Quadrum, equipped with everything you need for a small break at work and fresh snacks at all times. Become part of our purpose-driven, multicultural team now and help us create healthier futures

Full time

Affiliated Companies:

Affiliated Companies: World Courier (Lithuania) UAB

Prêt à postuler chez Cencora ?
Postuler chez Cencora

À propos de Cencora

Recruitment scams are on the rise and the intent is to target individuals looking for employment opportunities. To protect yourself, we urge you to be vigilant and follow these guidelines. ​1.) Research the Company: Thoroughly research any company before applying or sharing personal information, check their website, read reviews, and verify their legitimacy. 2.) Be Wary of Unrealistic Promises: Exercise caution If a job posting offers high salaries and minimal qualifications. Legitimate jobs will have realistic expectations and provide detailed job requirements. Jobs at Cencora can be found on Cencora.com/careers 3.) Guard Your Personal Information: Only share sensitive information after vet

Voir tous les emplois chez Cencora →

Emplois similaires

Lloyds Banking Group
WAF Security Engineer
Lloyds Banking Group
⚡ Postuler tôt Manchester Sur site £48,987–£55,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 h
HP
Systems Infrastructure & Network Security Operations Engineer
HP
⚡ Postuler tôt Spring, Texas, United States o... Sur site $93,400–$143,800
● Nouveau 👁 Vu ✓ Postulé il y a 2 h
HP
Cybersecurity Threat Detection & Response Engineer
HP
⚡ Postuler tôt Sant Cugat del Valles, Barcelo... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 h
HP
Software Product Security Engineer Intern
HP
⚡ Postuler tôt Spring, Texas, United States o... Sur site $72,800–$83,200
● Nouveau 👁 Vu ✓ Postulé il y a 2 h
Vertex Inc
Security Operations Engineer
Vertex Inc
⚡ Postuler tôt Remote USA · lieu restreint $91,200–$118,600
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
Vertex Inc
Senior AI Security Engineer
Vertex Inc
⚡ Postuler tôt Remote USA · lieu restreint $120,700–$156,900
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
MA
Oliver Wyman Vector - DevOps Engineer (AWS & Cybersecurity)
Marsh
⚡ Postuler tôt Atlanta - Hartsfield Sur site $90,000–$115,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
Anduril Industries
Senior Product Security Engineer
Anduril Industries
⚡ Postuler tôt Fort Collins, Colorado, United... Sur site $144,000–$191,000
● Nouveau 👁 Vu ✓ Postulé il y a 10 h
Gong.io
Senior Cloud Security Engineer
Gong.io
⚡ Postuler tôt Tel Aviv Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 10 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Cencora

Voir tous les emplois chez Cencora →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit