Engineering Senior Specialist

Merck Merck · Pharma · Bucuresti, Romania

Seeking an Engineering Senior Specialist to design, engineer, and operate enterprise-scale XDR and SIEM platforms across Microsoft and Google security ecosystems. This role focuses on security platform engineering, detection engineering, and operational resilience to improve threat detection, response effectiveness, data fidelity, and platform reliability. Requires deep hands-on engineering expertise, an operations-first mindset, and collaboration with SOC, cloud, identity, and infrastructure teams.

What you'd actually do

  1. Engineer, operate, and continuously optimize Microsoft Sentinel and Microsoft Defender XDR (Defender for Endpoint, Identity, Office, and Cloud).
  2. Engineer and operate Google Security Operations (Chronicle SIEM) to support high-volume security telemetry ingestion, analytics, and long-term retention.
  3. Design and maintain scalable ingestion architectures, including normalization, enrichment, routing, and retention across hybrid and multi-cloud environments.
  4. Ensure platform reliability, performance, cost awareness, and operational stability.
  5. Support detection tuning activities to reduce false positives, improve signal-to-noise ratio, and align with SOC workflows.

Skills

Required

  • security engineering
  • detection engineering
  • SOC engineering
  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Google Security Operations (Chronicle SIEM)
  • KQL
  • cloud security (Azure and/or GCP)
  • identity
  • endpoint
  • network telemetry
  • large, complex enterprise environments
  • Certificate Services
  • Cloud Security
  • Cyber Defense
  • Cybersecurity
  • Cybersecurity Analytics
  • Cybersecurity Operations
  • Data Quality Control
  • Delivery of Security Applications
  • Design Applications
  • Enterprise Resource Planning (ERP)
  • Identity Access Management (IAM)
  • Incident Investigations
  • Incident Response
  • Information Security
  • Microsoft Azure
  • Network Segmentation
  • Operational Technology (OT) Security
  • Regulatory Requirements
  • Security Analytics
  • Security Architecture Design
  • Security Architecture Review
  • Security Engineering
  • SLA Management
  • System Designs

Nice to have

  • SOAR
  • MITRE ATT&CK

What the JD emphasized

  • design, engineer, and operate enterprise-scale XDR and SIEM platforms
  • Microsoft and Google security ecosystems
  • security platform engineering
  • detection engineering
  • operational resilience
  • threat detection quality
  • response effectiveness
  • data fidelity
  • platform reliability
  • deep hands-on engineering expertise
  • operations-first mindset
  • SOC (CFC)
  • cloud
  • identity
  • infrastructure teams
  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Google Security Operations (Chronicle SIEM)
  • scalable ingestion architectures
  • platform reliability
  • performance
  • cost awareness
  • operational stability
  • detection tuning
  • false positives
  • signal-to-noise ratio
  • SOC workflows
  • incident investigation
  • threat hunting
  • response activities
  • MITRE ATT&CK
  • threat-informed defense principles
  • onboarding
  • validation
  • parsing
  • quality monitoring
  • security telemetry sources
  • logging and visibility gaps
  • data quality standards
  • detection
  • investigation
  • reporting
  • logging and monitoring practices
  • internal security standards
  • regulatory requirements
  • detection lifecycle management
  • enrichment
  • response orchestration
  • SOAR
  • native platform capabilities
  • standardization
  • documentation
  • runbook development
  • operational maturity
  • resiliency
  • platform roadmaps
  • reliability improvements
  • technical debt reduction initiatives
  • CFC/SOC
  • Cloud Security
  • Identity
  • Infrastructure
  • Compliance
  • audit and compliance activities
  • SOX
  • regulatory log‑retention requirements
  • technical input
  • onboarding decisions
  • platform changes
  • security architecture reviews
  • 5+ years of experience
  • security engineering
  • detection engineering
  • SOC engineering
  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Google Security Operations (Chronicle SIEM)
  • large-scale cloud SIEM platforms
  • KQL
  • structured detection logic
  • cloud security (Azure and/or GCP)
  • identity
  • endpoint
  • network telemetry
  • large, complex enterprise environments