JobHabor

SIEM/ SOAR Automation SME

Philips
Location
Amsterdam
Workplace
Hybrid
Employment
Salary
Apply on the employer’s site

Posted 2d ago

Job Title

SIEM/ SOAR Automation SME

Job Description

A SIEM/SOAR Automation Subject Matter Expert responsible for the ongoing operation, maintenance, and reliability of our primary Security Operations Center (SOC) platform. This business-critical role keeps security monitoring, data ingestion, and response automation dependable across Philips. The scope covers Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), and the supporting data pipelines and integrations.You will apply deep technical expertise and independent judgement under broad guidelines, working with the SOC, engineering teams, and service partners to resolve complex issues and improve platform performance and resilience.

The Philips Group Security team, dedicated to safeguarding our customers, employees, and partners worldwide. Within Group Security - Information Security (GS-IS), the Cybersecurity Processes and Tooling department develops and operates the capabilities that support enterprise cyber defense. You will work closely with the SOC, IAM, ITaaP, cloud and engineering teams, and external service providers.

Your role

  • Manage the operational health of SIEM, SOAR and Security Data Pipelines. Monitor availability, performance, capacity, and platform alerts, and drive recovery from failures that affect SOC visibility or response.
  • Evaluate releases and new features, optimize searches, and investigate failed searches and other platform integrations. Coordinate detection-related issues with the SOC.
  • Investigate complex data ingestion issues escalated by the first-line service team. Coordinating engineering changes and service restoration with managed service providers, platform teams and vendor support. Driving root-cause analysis and preventive actions for recurring issues.
  • Coordinate upgrades and engineering changes with the managed service teams. For vendor-managed SOAR Cloud releases, review release notes, assess impacts, approve or defer maintenance windows within agreed authority, and validate playbooks after upgrades.
  • Maintaining and improving SOAR playbooks, scripts and API integrations in collaboration with SOC analysts and automation-development peers. This includes safe testing, error handling, permissions management and post-change validation.
  • Supporting secure administration and operational management of data pipelines, including approved emergency load-distribution and routing changes where required.
  • Track service levels and define and report KPIs for platform health, ingestion reliability, failed searches, playbook execution, and incident resolution. Use findings to prioritize corrective actions and service improvements.
  • Maintain runbooks, configuration and integration documentation, operating procedures, and knowledge-transfer material. Participate in security and solution reviews, apply secure configuration and change controls, and support investigations with reliable platform data.
  • Coordinate vendors and internal stakeholders through incidents, maintenance, and releases.
  • Identifying and implementing practical AI-assisted automation opportunities that improve engineering productivity, platform reliability and SOC effectiveness, with appropriate validation and security controls.

You're the right fit

Minimum qualifications

  • Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or equivalent.
  • With a Bachelor's degree, a minimum of 2 years of relevant experience in Security Architecture, Network Security, Cybersecurity Technology, Information Security, or equivalent. With a Master's degree.

Technical and professional capabilities

  • Demonstrated hands-on experience supporting SIEM platforms, including search troubleshooting, performance monitoring, detection support, data onboarding and integration management.
  • Practical experience developing, maintaining, testing and troubleshooting SOAR playbooks, scripts and API integrations using Python, PowerShell or comparable technologies.
  • Understanding secure authentication, authorization, secrets management and least-privilege access when implementing automations and integrations.
  • Practical understanding of log collection, parsing, routing and delivery mechanisms, including syslog, HTTP Event Collector, APIs, queues and cloud-native ingestion patterns.
  • Working knowledge of cloud platforms, especially AWS and Azure, including cloud logging, identity, security services and integration patterns.
  • Ability to investigate complex service issues, assess operational risk, coordinate technical changes and restore critical services with internal teams and vendors.
  • Experience using AI-assisted development and automation responsibly to build, test, debug and maintain scripts, playbooks and integrations. Ability to validate AI-generated output for correctness, security and reliability before production use.
  • Strong documentation and reporting skills, including KPI analysis, service-level reporting and communication with both technical and non-technical stakeholders.
  • Ability to work independently, prioritize business-critical issues and communicate fluently in English.

Preferred qualifications

  • Experience supporting security platforms in a multinational environment and coordinating managed service providers. Familiarity with ServiceNow, MISP, Microsoft security and identity services, Splunk Cloud, or Microsoft Sentinel.
  • Familiarity with NIST and CIS security practices and ITIL service management. Relevant Splunk, cloud, Sentinel, or cybersecurity certifications are an advantage.

Compensation & benefits

Doing meaningful work should come with fair, transparent rewards. The base salary range for this role is EUR 61,200 - EUR 101,900. We determine pay within the range using objective factors, like the skills the role requires, your relevant experience and the responsibility you'll have in this role, alongside internal equity and local market considerations.

This role is eligible for 3% short term incentive with your rewards linked to both individual performance and company results. We’ll share the full approach with you during the interview process, so you can make a clear, informed decision. Benefits include hybrid working, paid time-off, health and wellbeing benefits, learning and development opportunities.

How we work together

We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week.

This role is an office role.

About Philips

We are a health technology company. We built our entire company around the belief that every human matters, and we won't stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help the lives of others.

  • Learn more about our business here.
  • Discover our rich and exciting history here.
  • Learn more about our purpose here.

If you're interested in this role and have many, but not all, of the experiences needed, we encourage you to apply. You may still be the right candidate for this or other opportunities at Philips. Learn more about our commitment to diversity and inclusion

here

.

Skills

  • SIEM
  • IAM
  • Python
  • PowerShell
  • HTTP
  • AWS
  • Azure
  • Cloud Logging
  • ServiceNow
  • Splunk
  • NIST

More jobs at Philips

All 35

Similar roles