SIEM Architect
TUI Group is the world’s number one integrated tourism business. Information Security is a global team within TUI technology responsible for maintaining and continuously improving security across TUI. We are a multi-disciplinary team of experts across Governance, Risk and Compliance (GRC), Architecture, Engineering and Delivery providing services across the UK, Ireland, Sweden, Norway, Denmark, Finland, Spain, Germany, Belgium and The Netherlands.
We never stop looking ahead, seeking new ways to delight our customers and grow our business. We recognise the power of digital and the massive contribution this brings to creating a truly unique and differentiated customer experience.
We are seeking an experienced SIEM Architect to join our global Cyber Security team that provides services to the whole of TUI Group. In this pivotal role, you will design, implement, and manage our Security Information and Event Management (SIEM) systems to protect TUI's digital assets. You will collaborate with cross-functional teams to enhance our security posture and ensure compliance with industry standards.
- Now taking applications until 20-01-2025
ABOUT OUR OFFER
- Personal benefits: Attractive remuneration, bonus opportunity, exclusive travel perks & discounts, extensive health & wellbeing support, and more.
- Flexible working: Work is something you do, not somewhere you go. We encourage a healthy work-life balance and offer hybrid or remote working models.
- A career to shape: Opportunities to upskill, reskill and grow your career. Access the TUI Tech Learning Hub to level-up and reach your ambitions.
- Expand your horizons: Participate in our tech communities and collaborate on global projects and teams.
- Community: Get involved with incredible local charity and sustainability initiatives like the TUI Care Foundation and the Sustainable Tech Community.
ABOUT THE JOB
Stakeholder Engagement & Roadmap Development:
- Engage with key stakeholders to understand business needs, security requirements, and priorities.
- Develop and maintain a SIEM roadmap aligned with organizational goals and emerging threats.
- Prioritize and manage a backlog of SIEM enhancements, features, and fixes based on stakeholder input.
- Communicate updates, progress, and changes to stakeholders and senior leadership.
- Facilitate regular meetings with stakeholders to gather feedback and adjust plans accordingly.
SIEM Architecture & Design:
- Develop and maintain the overall SIEM architecture to meet business and security requirements.
- Design scalable solutions for data collection, processing, and storage within the SIEM platform.
- Establish standards and best practices for SIEM deployment and configuration.
- Document architectural plans, roadmaps, configurations, and procedures.
SIEM Engineering & Implementation:
- Install, configure, and maintain SIEM platforms (e.g., Splunk) and associated components.
- Integrate various log sources, including servers, applications, and network devices, into the SIEM.
- Develop custom scripts and automation tools to streamline SIEM operations.
- Optimize SIEM performance through tuning and scaling.
Content Development & Management:
- Create and manage correlation searches, alerts, and dashboards to detect security threats.
- Develop use cases and implement monitoring strategies for threat detection and compliance.
- Regularly update SIEM content to adapt to emerging threats and business changes.
Monitoring & Incident Response Support:
- Collaborate with the Security Operations Centre (SOC) to analyse security events.
- Assist in incident response activities by providing relevant SIEM data and insights.
- Fine-tune detection rules to reduce false positives and enhance threat visibility.
Maintenance & Troubleshooting:
- Perform regular system health checks and ensure high availability of SIEM services.
- Troubleshoot and resolve issues related to data ingestion, parsing, and correlation.
- Apply patches and updates to maintain system security and compliance.
Collaboration & Training:
- Work closely with IT, DevOps, and other security teams to align on security objectives.
- Provide training and mentorship to team members on SIEM functionalities and best practices.
- Participate in cross-functional projects to enhance overall security posture.
Compliance & Reporting:
- Ensure SIEM operations comply with regulatory requirements and internal policies.
- Generate compliance reports for standards such as GDPR, PCI DSS, and ISO 27001.
- Support audit activities by providing necessary documentation and evidence.
ABOUT YOU
Education & Experience:
- Bachelor’s degree in Computer Science or equivalent experience, Information Security, or a related field.
- Proven experience in SIEM architecture and engineering roles.
Technical Expertise:
- Proficiency with SIEM platforms, especially Splunk Enterprise and Splunk Enterprise Security.
- Strong knowledge of log management, event correlation, and security analytics.
- Experience with data onboarding, including parsing, normalizing, and mapping data sources.
- Familiarity with network protocols, operating systems, and security technologies.
- Proficiency in scripting languages such as Python, PowerShell, or Bash.
Security Knowledge:
- Understanding of cybersecurity principles, threat landscapes, and attack vectors.
- Knowledge of security frameworks and compliance standards (e.g., NIST, ISO 27001, GDPR).
- Experience in developing and implementing security use cases and playbooks.
Analytical & Problem-Solving Skills:
- Ability to analyse complex datasets to identify patterns, anomalies, and security incidents.
- Strong troubleshooting skills to resolve technical issues promptly.
Communication & Collaboration:
- Excellent verbal and written communication skills.
- Ability to convey complex technical concepts to non-technical stakeholders.
- Experience working in cross-functional teams and global environments.
Certifications:
- Relevant certifications such as Splunk Certified Architect, Splunk Certified Engineer, CISSP, or CISM are highly desirable.
From a workplace to a place to belong. At TUI we embrace diversity, equity, and inclusion, encouraging everyone to come as you are, because together, our potential is limitless.
We are committed to supporting candidates with disabilities and impairments so if you require any support, please do let us know.
-
Carrièregebieden | Jobs & Carrières bij TUI In onze TUI-carrièregebieden creëren we elke dag onvergetelijke ervaringen. Ontdek hier onze teams, wat ze doen en wie ze zijn.
-
Over TUI | Jobs & Carrières bij TUI Meer informatie over TUI. Wij zijn dé naam in wereldwijde reis- en vrijetijdsbelevingen die vakantiedromen waarmaakt.
-
Het beste team in de reiswereld | Jobs & Carrières bij TUI Voor ons betekent "Let's TUI it" samen uitdagingen aanpakken en oplossingen vinden met een mentaliteit van aanpakken. Zie hier wat ons het beste team in de reiswereld.
-
-
Impressum | Jobs & Carrières bij TUI Vind hier onze impressum.
-
Neem contact op | Jobs & Carrières bij TUI Hier vind je de recruitmentteams binnen TUI die je graag helpen met je vragen.
-
-
Cookieverklaring | Jobs & Carrières bij TUI Jouw privacy is belangrijk voor ons. Hier vind je alle informatie over wat cookies zijn, hoe we ze gebruiken en welke keuzes je hebt wat betreft cookies.
-
-
-
-
Kantoorfuncties Bij TUI draait alles in onze bedrijfsfuncties om het mogelijk maken van een topvakantie voor onze gasten. Hier kun je belangrijke projecten starten, financiële doelen nastreven of onze medewerkers ondersteunen op hun weg.
-
Cruises We hebben een vloot van 16 cruiseschepen en navigeren door alle uitdagingen heen om onvergetelijke cruise-ervaringen te creëren die onze gasten hun leven lang zullen herinneren.
-
Vacatures in Hotels en Bestemmingen Begin met ons je droomcarrière in het buitenland. Er wachten onvergetelijke ervaringen op je. Of je nu op zoek bent naar avontuur of al op een van onze bestemmingen woont – we kunnen niet wachten tot je bij ons incheckt.
-
Retail en Contact Centers Er wachten veel carrièremogelijkheden op je in onze reisbureaus en callcenters – inclusief reislust. Word onderdeel van de TUI-familie en start een carrière die de harten van vakantiegangers sneller laat kloppen.
-
Early Careers Onze startersprogramma's zijn wereldwijd beschikbaar, en elke locatie heeft iets unieks te bieden. Ontdek wat we waar aanbieden.
-
Engineering en Onderhoud Of het nu gaat om het verkrijgen van de benodigde onderdelen, het naleven van strenge voorschriften of het onderhoud – we hebben alles onder controle en werken voortdurend aan het optimaliseren van de beschikbaarheid en prestaties van onze vloot.
-
Airline Stap aan boord bij TUI Airline, waar passie vleugels krijgt. Ons diverse team vormt het kloppend hart van onvergetelijke reizen en zorgt ervoor dat elke vakantie van onze klanten begint met een glimlach.
-
Tech, Digital en Data Innovaties in de reisbranche? Ons tech-team is er mee bezig! Of je nu enthousiast bent over softwareontwikkeling, data-analyse, UX/UI-design of cyberveiligheid – bij TUI vind je het perfecte platform om je carrière te lanceren.
-
Crystal Ski We’ve been taking people to the mountains for over 40 years to create unforgettable experiences in ince, snow and sun. Join us and make some of the world’s greatest ski resorts your home.
-
-
-
-
How We Hire | Destination Jobs At TUI we want to make your journey as a candidate as simple and transparent as we possibly can. We truly believe that your application to join TUI should be as exciting as going on holiday. Learn more about our application process.
-
-
-
-
-
Come as you are We weten dat mensen net zo divers zijn als de bestemmingen waar we onze klanten naartoe sturen. Net zoals reizen gaat over op verkenning gaan, zijn wij op reis om onze werkcultuur inclusiever te maken. Zo doen we diversiteit en inclusie bij TUI…
-
-
Jij zou hier kunnen zijn!
Ontdek de locatieBanen voor jou
-
Software EngineerPalma de Mallorca, ESP, Oporto, PT; Milan, IT; Flexible Rol bekijken
-
Information Security ManagerLisbon, PRT, Oporto, PT; Barcelona, ES; Madrid, ES; Flexible Rol bekijken
-
SIEM EngineerLisbon, PRT, Oporto, PT; Madeira, PT; Faro, PT; Flexible Rol bekijken
-
Incident Response ManagerLisbon, PRT, Oporto, PT; Madeira, PT; Faro, PT; Flexible Rol bekijken