
AI Governance and Compliance Specialist IRC260565
- Kraków, małopolskie
- Stała
- Pełny etat
You’ll be responsible for designing and onboarding robust log monitoring solutions, ensuring complete and correct ingestion of log data, and maintaining long-term operational health. While Google SecOps experience is a bonus, we are specifically looking for individuals with strong expertise in other enterprise SIEMs—such as Splunk, Microsoft Sentinel, QRadar, or Sumo Logic—who are ready to apply their skills in a new platform.Requirements
- Proven hands-on experience with enterprise SIEM platforms (e.g., Splunk, Sentinel, QRadar, Sumo Logic).
- Deep understanding of log ingestion pipelines, formatting standards (JSON, Syslog, CEF), and parsing methodologies.
- Ability to build and manage SIEM health monitoring mechanisms—not threat detections, but operational checks.
- Experience writing and tuning queries/rules in SPL, KQL, regex, or similar.
- Strong troubleshooting and problem-solving skills with a high attention to detail.
- Comfortable supporting multiple client environments and balancing delivery with operations.
- Exposure to or interest in Google Chronicle / Google SecOps (training will be provided).
- Experience in MSSP or security consulting environments.
- Familiarity with GCP logging tools and integrations.
- Scripting experience (Python, bash, etc.) for automation and validation tasks.
- Well-versed in Linux, especially in relation to log management and system troubleshooting.
- Design and implement SIEM monitoring environments using Google SecOps for a variety of clients.
- Lead log onboarding efforts, integrating and validating log sources across cloud, network, endpoint, and infrastructure environments.
- Configure and maintain health-related detections and alerting rules to monitor:
– Parsing accuracy and format consistency
– Pipeline or integration failures
- Monitor solution health and proactively respond to operational issues to ensure “lights are always on.”
- Troubleshoot data gaps, ingestion failures, and mis-parsed logs across multiple client environments.
- Collaborate with project managers, internal engineers, and client stakeholders during both deployment and steady-state phases.
- Maintain clear documentation and provide technical support across the delivery and operational lifecycle.