Information Security Engineer III
World Courier · Vilnius
Job description
About the role
This is a hands‑on engineering position responsible for the end‑to‑end security data pipeline and the detection content it powers. You will onboard, parse, normalize, and route log and telemetry data into the SIEM and data lake, and build high‑fidelity detections that turn raw telemetry into actionable alerts.
Key responsibilities
- Onboard security and operational log sources (endpoints, servers, network devices, cloud services, SaaS) into a centralized logging pipeline.
- Develop and maintain parsers and normalization logic to ensure consistent schema and field usability for downstream detection.
- Implement routing logic to multiple destinations such as SIEM, data lake, and archival storage, applying categorization to separate security‑relevant data.
- Operate and troubleshoot the data pipeline platform (e.g., Databahn, Cribl), monitoring source health and ingestion failures.
- Ensure collection, enrichment, and availability of identity, endpoint, and behavioral data for UEBA and analytics.
- Build and maintain compliance dashboards and reporting for audit and regulatory requests.
- Contribute to log‑source integration for M&A and new entity onboarding.
- Design, tune, and maintain static/rule‑based and dynamic/behavioral detections covering malicious and anomalous activity.
- Document runbooks for each production detection and ensure alerts are high‑fidelity and actionable.
- Participate in detection simulations and adversary emulation exercises based on MITRE ATT&CK.
Required profile
- Individual contributor with the ability to work independently on assigned domains.
- Experience guiding less‑experienced engineers through peer review and pairing.
- Strong analytical mindset for translating raw log data into meaningful security detections.
Required skills
- SIEM platforms
- Data lake technologies
- Databahn or equivalent data‑pipeline tools
- Cribl or similar log processing solutions
- UEBA (User and Entity Behavior Analytics)
- MITRE ATT&CK framework for detection design
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Lithuania.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 weeks ago
Expires 1 month from now
44 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
World Courier
Vilnius