Engineer III - Information Security
AmerisourceBergen is now Cencora! Explore our careers.
·Today
- Location
- NCEE > Lithuania > Vilnius > Konstitucijos
- Type
- Full-time
- Department
- Engineering
- Source
- Workday
Description
Cencora, previously known as AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving lives. Ranked #21 on the Global Fortune 500, our team members are united in our responsibility to create healthier futures.
Our Shared Service Center in Lithuania is experiencing rapid growth and we have many diverse and exciting roles in Customer Service, Operations, IT, Finance and HR. Join us and make a positive impact on human and animal health.
Job Details
Hands-on engineering role spanning the security data pipeline and the detection content it powers. Onboards, parses, normalizes, and routes log and telemetry data into the SIEM and data lake, and builds and tunes the detections that turn that telemetry into high-fidelity, actionable alerts. This is a full individual-contributor role for an engineer who wants ownership of the end-to-end path from raw log source to validated detection, without the artificial handoff between "data" and "detection" work. Reports to Principal Engineer or Head of Cyber Defense Engineering. Individual contributor - no direct reports. Expected to work independently on assigned domains and to guide less experienced engineers informally through peer review and pairing.
Responsibilities:
Data Pipeline & Telemetry
Onboard security and operational log sources - endpoints, workstations, servers, network devices, cloud services, and SaaS - into the centralized logging pipeline.
Build and maintain parsers and normalization logic to ensure schema consistency and field-level usability for downstream detection and correlation.
Implement and maintain data forking/routing logic to multiple destinations, including SIEM, data lake, and archival storage.
Apply categorization logic that separates security-relevant from operational data, tuning cost and signal-to-noise across destinations.
Operate day-to-day on the data pipeline platform (Databahn, Cribl, or equivalent), including source health monitoring and troubleshooting ingestion failures.
Ensure the identity, endpoint, and behavioral data required for UEBA and behavioral analytics is collected, enriched, and available.
Build and maintain compliance and coverage dashboards and reporting from log data to support audit and regulatory requests.
Contribute to log-source integration for M&A and entity-onboarding activity under the direction of a lead.
Detection Engineering
Build and maintain detections - both static/rule-based and dynamic/behavioral - covering malicious and anomalous activity across the environment.
Own assigned detection content through its lifecycle: continuously tune existing rules and develop new use cases as adversary TTPs evolve.
Ensure alerts are high-fidelity, actionable, and mapped to real risk, with a documented runbook accompanying every production detection.
Participate in detection simulations and adversary emulation exercises (MITRE ATT&CK based) to validate coverage and drive down false positives.
Work directly with SOC Analysts on the triage feedback loop, and with Threat Intelligence on emerging TTPs and IOCs, converting both into detection content.
Maintain the detection coverage map against MITRE ATT&CK for assigned domains and surface gaps, including gaps caused by missing telemetry.
Follow and help improve detection engineering standards: documentation, version control, peer review, and testing/CI for detection content.
Cross-Cutting
Close the loop between the two domains: translate detection data gaps into pipeline onboarding or parsing work, and validate that newly onboarded data is fit for detection purposes.
Participate in peer review of both parser/pipeline changes and detection content.
Support on-call or escalation rotation for pipeline and detection platform issues as required.
Work Experience:
4-6 years in security engineering, SIEM engineering, detection/content engineering, or security data pipeline engineering, with demonstrable hands-on delivery in at least one of the two domains and working capability in the other.
Hands-on Splunk engineering experience covering both sides: data onboarding, parsing/field extraction, and source-type design, plus writing and tuning SPL correlation searches.
Practical experience with a log pipeline/data routing platform (Databahn, Cribl, or comparable) for ingestion, parsing, normalization, and multi-destination routing.
Working understanding of MITRE ATT&CK and the ability to translate adversary techniques into detection logic.
Working knowledge of endpoint, network, cloud, and identity/IAM telemetry - both the parsing challenges each presents and how each informs detection design.
Scripting and automation skills (Python or similar) applied to parser development, detection-as-code, testing, or enrichment.
Experience contributing to detection validation, atomic testing, or purple-team exercises.
Preferred Certifications:
Relevant certifications (Splunk Certified Admin/Architect, GCDA, GCIA, GCTI, or equivalent).
Skills and Knowledge:
Experience integrating log data into a data lake/lakehouse platform for large-scale storage and analytics.
Exposure to UEBA-driven and behavioral analytics, not only signature-based detection.
Familiarity with detection-as-code frameworks (Sigma, version-controlled detection repos, CI/CD for content).
Familiarity with cost/volume optimization for high-volume log pipelines (filtering, sampling, tiered storage).
Experience with Splunk/ReliaQuest GreyMatter or a comparable SIEM/AI SOC platform.
Experience supporting log-source integration during M&A or entity onboarding.
Experience building compliance dashboards and reporting from log data.
Salary: 4510 - 6444 EUR gross monthly
# Li-hybrid
What Cencora offers
We offer a competitive annual bonus, life insurance from Day 1, a best-in-class health insurance package, and up to 6 fully paid benefit days a year. As a Cencora employee, you have the benefit of our referral bonus scheme, our boundless learning opportunities and our global Employee Assistance Program. We have a wonderful office location in Quadrum, equipped with everything you need for a small break at work and fresh snacks at all times. Become part of our purpose-driven, multicultural team now and help us create healthier futures
Full time