Hiring.Camp

Engineer III - Information Security

AmerisourceBergen is now Cencora! Explore our careers.

·

Today

Location
NCEE > Lithuania > Vilnius > Konstitucijos
Type
Full-time
Department
Engineering
Source
Workday

Description

Cencora, previously known as AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving lives. Ranked #21 on the Global Fortune 500, our team members are united in our responsibility to create healthier futures.

Our Shared Service Center in Lithuania is experiencing rapid growth and we have many diverse and exciting roles in Customer Service, Operations, IT, Finance and HR.  Join us and make a positive impact on human and animal health.

Job Details

Hands-on engineering role spanning the security data pipeline and the detection content it powers. Onboards, parses, normalizes, and routes log and telemetry data into the SIEM and data lake, and builds and tunes the detections that turn that telemetry into high-fidelity, actionable alerts. This is a full individual-contributor role for an engineer who wants ownership of the end-to-end path from raw log source to validated detection, without the artificial handoff between "data" and "detection" work. Reports to Principal Engineer or Head of Cyber Defense Engineering. Individual contributor - no direct reports. Expected to work independently on assigned domains and to guide less experienced engineers informally through peer review and pairing. 

Responsibilities:

Data Pipeline & Telemetry

  • Onboard security and operational log sources - endpoints, workstations, servers, network devices, cloud services, and SaaS - into the centralized logging pipeline. 

  • Build and maintain parsers and normalization logic to ensure schema consistency and field-level usability for downstream detection and correlation. 

  • Implement and maintain data forking/routing logic to multiple destinations, including SIEM, data lake, and archival storage. 

  • Apply categorization logic that separates security-relevant from operational data, tuning cost and signal-to-noise across destinations. 

  • Operate day-to-day on the data pipeline platform (Databahn, Cribl, or equivalent), including source health monitoring and troubleshooting ingestion failures. 

  • Ensure the identity, endpoint, and behavioral data required for UEBA and behavioral analytics is collected, enriched, and available. 

  • Build and maintain compliance and coverage dashboards and reporting from log data to support audit and regulatory requests. 

  • Contribute to log-source integration for M&A and entity-onboarding activity under the direction of a lead. 

Detection Engineering 

  • Build and maintain detections - both static/rule-based and dynamic/behavioral - covering malicious and anomalous activity across the environment. 

  • Own assigned detection content through its lifecycle: continuously tune existing rules and develop new use cases as adversary TTPs evolve. 

  • Ensure alerts are high-fidelity, actionable, and mapped to real risk, with a documented runbook accompanying every production detection. 

  • Participate in detection simulations and adversary emulation exercises (MITRE ATT&CK based) to validate coverage and drive down false positives. 

  • Work directly with SOC Analysts on the triage feedback loop, and with Threat Intelligence on emerging TTPs and IOCs, converting both into detection content. 

  • Maintain the detection coverage map against MITRE ATT&CK for assigned domains and surface gaps, including gaps caused by missing telemetry. 

  • Follow and help improve detection engineering standards: documentation, version control, peer review, and testing/CI for detection content. 

Cross-Cutting 

  • Close the loop between the two domains: translate detection data gaps into pipeline onboarding or parsing work, and validate that newly onboarded data is fit for detection purposes. 

  • Participate in peer review of both parser/pipeline changes and detection content. 

  • Support on-call or escalation rotation for pipeline and detection platform issues as required. 

Work Experience:

  • 4-6 years in security engineering, SIEM engineering, detection/content engineering, or security data pipeline engineering, with demonstrable hands-on delivery in at least one of the two domains and working capability in the other. 

  • Hands-on Splunk engineering experience covering both sides: data onboarding, parsing/field extraction, and source-type design, plus writing and tuning SPL correlation searches. 

  • Practical experience with a log pipeline/data routing platform (Databahn, Cribl, or comparable) for ingestion, parsing, normalization, and multi-destination routing. 

  • Working understanding of MITRE ATT&CK and the ability to translate adversary techniques into detection logic. 

  • Working knowledge of endpoint, network, cloud, and identity/IAM telemetry - both the parsing challenges each presents and how each informs detection design. 

  • Scripting and automation skills (Python or similar) applied to parser development, detection-as-code, testing, or enrichment. 

  • Experience contributing to detection validation, atomic testing, or purple-team exercises. 

Preferred Certifications:

  • Relevant certifications (Splunk Certified Admin/Architect, GCDA, GCIA, GCTI, or equivalent). 

Skills and Knowledge:

  • Experience integrating log data into a data lake/lakehouse platform for large-scale storage and analytics. 

  • Exposure to UEBA-driven and behavioral analytics, not only signature-based detection. 

  • Familiarity with detection-as-code frameworks (Sigma, version-controlled detection repos, CI/CD for content). 

  • Familiarity with cost/volume optimization for high-volume log pipelines (filtering, sampling, tiered storage). 

  • Experience with Splunk/ReliaQuest GreyMatter or a comparable SIEM/AI SOC platform. 

  • Experience supporting log-source integration during M&A or entity onboarding. 

  • Experience building compliance dashboards and reporting from log data. 

Salary: 4510 - 6444 EUR gross monthly

# Li-hybrid

What Cencora offers

We offer a competitive annual bonus, life insurance from Day 1, a best-in-class health insurance package, and up to 6 fully paid benefit days a year. As a Cencora employee, you have the benefit of our referral bonus scheme, our boundless learning opportunities and our global Employee Assistance Program. We have a wonderful office location in Quadrum, equipped with everything you need for a small break at work and fresh snacks at all times. Become part of our purpose-driven, multicultural team now and help us create healthier futures

Full time

Affiliated Companies:

Affiliated Companies: World Courier (Lithuania) UAB

Skills

PythonCI/CDSIEMSOCSplunkComplianceCustomer Service

Similar Jobs

30

Engineer III

Jci · Wuxi - Changjiang Road, China

Today

Engineer III

City of Pasco · City of Pasco, WA, WA, US · Onsite

Yesterday

Engineer III

Dukeenergy · Clearwater FL Complexes, United States of America +1 · Hybrid

Yesterday

Engineer III

Marriott Hotels & Resorts · Tampa, FL, United States, US

2 days ago

Engineer III

Marriott Hotels & Resorts · Houston, TX, United States

5 days ago

Engineer III

Marriott Hotels & Resorts · Savannah, GA, United States, US

5 days ago

Engineer III

Lockwood Andrews & Newnam Inc · San Antonio, TX

5 days ago

Engineer III

Elevancehealth · IN-INDIANAPOLIS, 220 VIRGINIA AVE, United States of America +2 · Remote, Hybrid, Onsite

1 week ago

Engineer III

Marriott Hotels & Resorts · Philadelphia, PA, United States, US

1 week ago

Engineer III

Tyson Foods · Fayetteville Complex - Fayetteville, Arkansas, United States of America

1 week ago

Engineer III

Nc · Downtown Raleigh Wake, United States of America

1 week ago

Engineer III

Marriott Hotels & Resorts · Lake Buena Vista, FL, United States, US

1 week ago

Engineer III

Fairfax County · FAIRFAX (EJ32), VA, VA, US

1 week ago

Engineer III

Tyson Foods · Corporate - Springdale, Arkansas, United States of America · Onsite

1 week ago

Engineer III

Tyson Foods, Inc. · Corporate - Springdale, Arkansas, United States of America · Onsite

1 week ago

Engineer III

Nc · State Road Maint Wake, United States of America

1 week ago

Engineer III

Default Brand · Hayward, CA

1 week ago

Engineer III

Merit · Tijuana, Mexico

2 weeks ago

Engineer III

Marriott Hotels & Resorts · Austin, TX, United States

3 weeks ago

Engineer III

Marriott Hotels & Resorts · Bloomington, MN, United States, US

3 weeks ago

Engineer III

Ing · Bruxelles Avenue Marnix (ING), Belgium

3 weeks ago

Engineer III

Marriott Hotels & Resorts · Kapalua, HI, United States, US

3 weeks ago

Engineer III

Jci · Wuxi - Changjiang Road, China

4 weeks ago

Engineer III

Loewshotels · PA - Philadelphia - Loews Philadelphia Hotel, United States of America

4 weeks ago

Engineer III

Lockwood Andrews & Newnam Inc · Fort Worth, TX

1 month ago

Engineer III

Shhotelsandresorts · USA TN 1 Hotel Nashville, United States of America

1 month ago

Engineer III

Nexperia · Seremban, Malaysia

1 month ago

Engineer III

Default Brand · Pulau Pinang, MY, Malaysia

1 month ago

Engineer III

Yokogawa · YCA_Newnan Office, United States of America

1 month ago

Developer III

American Bureau of Shipping (ABS) · Houston, TX, United States

1 month ago
Engineer III - Information Security at AmerisourceBergen is now Cencora! Explore our careers. | Hiring.Camp