Senior Cyber Security Specialist – SIEM Governance, Monitoring & Logging
You have a strong drive to help keep VodafoneZiggo secure and take ownership of that topic. You enjoy combining deep security knowledge with a broad view of the organisation. Turning security risks and new threats into practical improvements gives you energy. You communicate clearly with technical teams, security specialists and external providers and know how to bring people along in change.
- You have at least 5 years of experience in Cyber Security, Security Monitoring or a similar field
- You have solid experience with SIEM Solutions, security logging and security detection
- You understand how logs from different systems are collected, analysed and used for security monitoring
- You can assess the quality, coverage and effectiveness of security detections
- You can translate cyber threats, risks and regulatory requirements into monitoring improvements
- You have experience working with or managing external security providers
- You can independently perform analyses and set up a proof of concept
- You move easily between different teams and providers and bring people along in improvements
Strategy, requirements and governance
- Set principles and standards for security-event logging, data collection, retention, normalisation, enrichment and monitoring coverage.
- Translate CSIRT needs, cyber risk, threat intelligence and regulatory requirements into prioritised requirements for the SIEM service, logging and detection use cases.
- Work with the internal security tooling team to define and maintain the strategic vision, target operating model and roadmap for SIEM, security monitoring and logging.
- Define governance, KPIs, KRIs and reporting that measure monitoring coverage, detection effectiveness, log quality and service performance.
Quality and continuous improvement
- Assess detection coverage, false positives, visibility gaps, log-source health and incident lessons learned, and drive prioritised improvement plans.
- Set quality controls for logging completeness, data integrity, retention, use-case testing and change acceptance.
- Provide clear assurance and advice to the CISO, CSIRT and senior stakeholders on risks, effectiveness and investment priorities.
Supplier and service assurance
- Conduct service reviews with the external SIEM/SOC provider; challenge performance, alert quality, use-case tuning, log onboarding and remediation of agreed actions.
- Assure that the supplier meets agreed SLAs, control requirements and quality standards; escalate material risks and recurring issues.
- Coordinate with the internal SIEM architecture and technical-owner team to align service requirements, technical changes, integration priorities and lifecycle decisions.