Specialist SIEM Engineering & Incident Response (Mainz, RP, DE, 55131)

Mainz, Germany Type not listed
Notify me about similar jobs

BioNTech is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

Mainz, Germany   |   full time   |   Job ID: 11706

About the role:

As Specialist SIEM Engineering & Incident Response you are responsible for supporting our CSIRT operations with a focus on SIEM onboarding, connector health, operational monitoring, stakeholder enablement, and foundational forensic and threat hunting capabilities. The role combines shared daily security operations responsibilities with technical ownership for improving Microsoft Sentinel and Defender integrations, maintaining SIEM service quality, and supporting business stakeholders with specific logging and monitoring requirements.

In addition, this role contributes to daily operational activities such as phishing analysis, incident investigation, escalated SOC case handling, third-party incident assessments, and incident response support.

Your contribution:

Perform daily security operations tasks, including analysis of phishing emails, handling of escalated security incidents, and support for incident response activities

Act as L3 support for incidents escalated by the external MSSP SOC provider and contribute to investigation, coordination, and response activities

Maintain, improve, troubleshoot, and expand Microsoft Sentinel and Microsoft Defender connectors, data integrations, and onboarding of relevant log sources

Monitor SIEM and related security platform health, including connectors, tables, automations, ingestion status, data quality, and service reliability

Analyze SIEM data consumption and support optimization of data onboarding, cost efficiency, and monitoring effectiveness

Serve as contact person for business and technical stakeholders with specific SIEM and monitoring requirements, including KRITIS-related applications and other critical systems

Define and establish clear guidelines and intake processes for system owners and stakeholders to report onboarding, monitoring, and use case requirements to the CSIRT team

Support basic forensic activities, including initial evidence collection, log review, timeline support, and preservation of relevant information in line with internal procedures

Perform basic threat hunting activities using Microsoft Defender and Sentinel capabilities, including workbooks, threat intelligence enrichment, data exploration, and hypothesis-driven analysis

Contribute to the continuous improvement of security monitoring coverage, visibility, documentation, and operational processes

A good match:

Bachelor’s degree in Information Security, Computer Science, Information Technology, or a comparable field; alternatively, equivalent practical experience

Several years of experience in IT security operations, SIEM engineering, SOC, or related security monitoring functions

Hands-on experience with Microsoft Sentinel and/or Microsoft Defender, especially in connector management, data onboarding, monitoring, and troubleshooting

Experience with log analysis, event correlation, and integration of enterprise systems into SIEM platforms

Basic practical experience in digital forensics, incident investigation support, or evidence handling

Initial experience or strong interest in threat hunting, security analytics, and proactive detection improvement

Experience working with internal stakeholders to gather technical requirements and translate them into monitoring or security use cases

Understanding of enterprise IT systems, application landscapes, interfaces, and dependencies relevant for security monitoring

Experience with documentation, process definition, and service-oriented operational support is beneficial

Strong knowledge of SIEM data flows, connector architectures, log source onboarding, and monitoring health indicators

Familiarity with KQL, workbook creation, and Microsoft security ecosystem capabilities

Basic understanding of forensic principles, chain of custody, and evidence preservation

Ability to translate stakeholder requirements into structured technical implementation steps

Strong organizational skills and a structured, service-oriented way of working

Good communication skills for interaction with system owners, business stakeholders, and external providers

Analytical mindset with attention to detail and a focus on operational quality

Security certifications such as SC-200, BTL1, AZ-500, GCFA (basic exposure), or similar are beneficial

Your Benefits:

It's our priority to support you:

Your flexibility: flexible hours | vacation account

Your growth: Digital Learning | Performance & talent development | leadership development | Apprenticeships | LinkedIn Learning

Your value: Your voice at the table | Culture on an equal footing | Opportunities to shape & impact | Support for your full potential

Your health and lifestyle: Company bike

Your mobility: Job ticket | Deutschlandticket

Your life phases: Employer-funded pension | Childcare

Apply now - We look forward to your application!

Apply to our Mainz, Germany   location by sending us your documents via our online form. For any questions, contact our talent acquisition team on: + 49 (0) 6131-9084-1291 (Monday-Friday from 1 PM to 3 PM CET).

Job ID 11706 (please always specify if you have any questions)

By submitting your application, you acknowledge that a background check will be conducted as part of the recruitment process in accordance with applicable laws and regulations. If you are considered for the position, BioNTech will conduct the background check through our service provider ‘HireRight’. You will be informed accordingly by your BioNTech-Recruiter.

]]>

Job details

Seniority
Not listed
Function
Other / Corporate Functions
Therapeutic area
Not listed
Location
Mainz, Germany
Employment type
Not listed

How this role compares

Computed from every other active Other / Corporate Functions role in our database, not just this employer's listings.

We don't have enough classified peer data for this role yet, so there's no comparison to show. This happens when a posting's title/category doesn't match any taxonomy rule -- it's excluded rather than compared against the wrong peer group.

Notify me about similar jobs

Get an email when we spot other openings like this one – same job function, comparable seniority, roles you'd actually want to see.