Specialist SIEM Engineering & Incident Response
Job description
Mainz, Germany | full time | Job ID: 11706
About the role:
As Specialist SIEM Engineering & Incident Response you are responsible for supporting our CSIRT operations with a focus on SIEM onboarding, connector health, operational monitoring, stakeholder enablement, and foundational forensic and threat hunting capabilities. The role combines shared daily security operations responsibilities with technical ownership for improving Microsoft Sentinel and Defender integrations, maintaining SIEM service quality, and supporting business stakeholders with specific logging and monitoring requirements.
In addition, this role contributes to daily operational activities such as phishing analysis, incident investigation, escalated SOC case handling, third-party incident assessments, and incident response support.
Your contribution:
- Perform daily security operations tasks, including analysis of phishing emails, handling of escalated security incidents, and support for incident response activities
- Act as L3 support for incidents escalated by the external MSSP SOC provider and contribute to investigation, coordination, and response activities
- Maintain, improve, troubleshoot, and expand Microsoft Sentinel and Microsoft Defender connectors, data integrations, and onboarding of relevant log sources
- Monitor SIEM and related security platform health, including connectors, tables, automations, ingestion status, data quality, and service reliability
- Analyze SIEM data consumption and support optimization of data onboarding, cost efficiency, and monitoring effectiveness
- Serve as contact person for business and technical stakeholders with specific SIEM and monitoring requirements, including KRITIS-related applications and other critical systems
- Define and establish clear guidelines and intake processes for system owners and stakeholders to report onboarding, monitoring, and use case requirements to the CSIRT team
- Support basic forensic activities, including initial evidence collection, log review, timeline support, and preservation of relevant information in line with internal procedures
- Perform basic threat hunting activities using Microsoft Defender and Sentinel capabilities, including workbooks, threat intelligence enrichment, data exploration, and hypothesis-driven analysis
- Contribute to the continuous improvement of security monitoring coverage, visibility, documentation, and operational processes
A good match:
- Bachelor’s degree in Information Security, Computer Science, Information Technology, or a comparable field; alternatively, equivalent practical experience
- Several years of experience in IT security operations, SIEM engineering, SOC, or related security monitoring functions
- Hands-on experience with Microsoft Sentinel and/or Microsoft Defender, especially in connector management, data onboarding, monitoring, and troubleshooting
- Experience with log analysis, event correlation, and integration of enterprise systems into SIEM platforms
- Basic practical experience in digital forensics, incident investigation support, or evidence handling
- Initial experience or strong interest in threat hunting, security analytics, and proactive detection improvement
- Experience working with internal stakeholders to gather technical requirements and translate them into monitoring or security use cases
- Understanding of enterprise IT systems, application landscapes, interfaces, and dependencies relevant for security monitoring
- Experience with documentation, process definition, and service-oriented operational support is beneficial
- Strong knowledge of SIEM data flows, connector architectures, log source onboarding, and monitoring health indicators
- Familiarity with KQL, workbook creation, and Microsoft security ecosystem capabilities
- Basic understanding of forensic principles, chain of custody, and evidence preservation
- Ability to translate stakeholder requirements into structured technical implementation steps
- Strong organizational skills and a structured, service-oriented way of working
- Good communication skills for interaction with system owners, business stakeholders, and external providers
- Analytical mindset with attention to detail and a focus on operational quality
- Security certifications such as SC-200, BTL1, AZ-500, GCFA (basic exposure), or similar are beneficial
Your Benefits:
It's our priority to support you:
- Your flexibility: flexible hours | vacation account
- Your growth: Digital Learning | Performance & talent development | leadership development | Apprenticeships | LinkedIn Learning
- Your value: Your voice at the table | Culture on an equal footing | Opportunities to shape & impact | Support for your full potential
- Your health and lifestyle: Company bike
- Your mobility: Job ticket | Deutschlandticket
- Your life phases: Employer-funded pension | Childcare
Apply now - We look forward to your application!
Apply to our Mainz, Germany location by sending us your documents via our online form. For any questions, contact our talent acquisition team on: + 49 (0) 6131-9084-1291 (Monday-Friday from 1 PM to 3 PM CET).
Job ID 11706 (please always specify if you have any questions)
By submitting your application, you acknowledge that a background check will be conducted as part of the recruitment process in accordance with applicable laws and regulations. If you are considered for the position, BioNTech will conduct the background check through our service provider ‘HireRight’. You will be informed accordingly by your BioNTech-Recruiter.
Inspired? Become part of #TeamBioNTech.
BioNTech, the story
At BioNTech, we are more than just a biotechnology company – we are a community of innovators, scientists, and leaders dedicated to revolutionizing medicine by translating cutting-edge science into survival. Your contributions here have the potential to improve the health of people worldwide, especially by addressing diseases with high medical needs like cancer and various infectious diseases.
Experience a dynamic workplace that embraces diversity in all its forms. We foster innovation, encourage creativity, and develop business strategies driven by our shared passion for advancing medicine.
Working at BioNTech means striving to achieve medical breakthroughs while growing your career in a meaningful way. Apply today and become part of a mission that has the potential to change lives around the world.
BioNTech does not tolerate discrimination, favoritism or harassment based on gender, political views, religion or belief, nationality, ethnic or social origin, age, sexual orientation, marital status, disability, physical appearance, health status or any other physical or personal characteristics. BioNTech is committed to creating a diverse and inclusive work environment. We are proud to be an equal opportunity employer. The main thing is that you suit us, and we suit you!
BioNTech - As unique as you
© 2024 BioNTech SE. All rights reserved
Cookie Consent Manager
We use cookies to give you the best possible website experience. Your cookie settings are stored in the local memory of your browser. These include cookies that are absolutely necessary for the operation of the website and additional cookies for a more convenient use of the website or for personalized content. You can decide at any time whether you want to accept or reject these additional cookies. If you do not accept all cookies, your experience with the website and services may be impaired. Further information can be found in our Privacy Statement and Cookie Statement.
Necessary cookies
These cookies are required to use this website and can't be turned off.
| Provider | Description | Enabled |
|---|---|---|
| SAP as service provider |
We use the following session cookies, which are all required to enable the website to function:
|
Cookies from provider SAPasserviceprovider are required and cannot be turned off
|
Functional Cookies
These cookies provide a better customer experience on this site, such as by remembering your login details, optimizing video performance, or providing us with information about how our site is used. You may freely choose to accept or decline these cookies at any time. Note that certain functionalities that these third-parties make available may be impacted if you do not accept these cookies.
| Provider | Description | Enabled |
|---|---|---|
| YouTube |
YouTube is a video-sharing service where users can create their own profile, upload videos, watch, like, and comment on videos. Opting out of YouTube cookies will disable your ability to watch or interact with YouTube videos.
Cookie Policy Privacy Policy Terms and Conditions |
Consent to cookies from provider YouTube
|