Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 23, 2026.
Cencora, previously known as AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving lives. Ranked #21 on the Global Fortune 500, our team members are united in our responsibility to create healthier futures.
Our Shared Service Center in Lithuania is experiencing rapid growth and we have many diverse and exciting roles in Customer Service, Operations, IT, Finance and HR. Join us and make a positive impact on human and animal health.
Job Details
Hands-on engineering role focused on the security data pipeline that supports enterprise logging, monitoring, analytics, compliance, and downstream detection needs. Onboards, parses, normalizes, enriches, and routes log and telemetry data into the SIEM, data lake, and archival platforms. This is a full individual-contributor role for an engineer who wants ownership of the end-to-end path from raw log source to trusted, usable security data.
Responsibilities:
- Onboard assigned security and operational log sources - endpoints, workstations, servers, network devices, and cloud services - into the centralized logging pipeline using established standards and patterns.
- Parse, normalize, and validate incoming data to improve consistency, schema alignment, and usability for downstream analysis and correlation.
- Configure and maintain approved data routing logic to support delivery to destinations such as the SIEM, data lake, archival storage, and other authorized platforms.
- Apply established categorization logic to help distinguish security-relevant data from non-security or operational data and support cost and signal-to-noise optimization.
- Operate and support the data pipeline platform (Databahn or equivalent) for centralized log collection, monitoring support, and reliable security data delivery at scale.
- Support UEBA use cases by ensuring assigned identity, endpoint, and behavioral data sources are collected, enriched, and available for behavioral analytics on users and systems.
- Build and maintain assigned compliance reporting and dashboards using available log data to support audit, regulatory, and operational reporting needs.
- Support logging integration for M&A or entity onboarding activities by implementing assigned log-source onboarding, validation, and issue-resolution tasks against defined timelines.
- Support SIEM log aggregation and correlation needs by ensuring assigned sources are onboarded, parsed, enriched, and available for detection and monitoring use cases.
- Contribute to team knowledge sharing by documenting onboarding patterns, troubleshooting steps, parser logic, and operational procedures for repeatable execution.
Work Experience:
- 4-6 years in security engineering, SIEM engineering, or security data pipeline engineering, with demonstrable hands-on delivery in log onboarding, parsing, normalization, enrichment, routing, or pipeline operations.
- Hands-on Splunk engineering experience covering data onboarding, parsing, field extraction, source-type design, ingestion health, and data-quality troubleshooting.
- Practical experience with a log pipeline/data routing platform (Databahn, Cribl, or comparable) for ingestion, parsing, normalization, and multi-destination routing.
- Working knowledge of endpoint, network, cloud, and identity/IAM telemetry, including the parsing, normalization, enrichment, and routing challenges each presents.
- Scripting and automation skills (Python or similar) applied to parser development, data-quality checks, enrichment workflows, pipeline testing, or operational automation.
Skills and Knowledge:
- Preferred experience integrating log data into a data lake/lakehouse platform for large-scale storage and analytics.
- Preferred exposure to behavioral analytics data requirements, including the identity, endpoint, and activity telemetry needed to support them.
- Nice to have familiarity with cost/volume optimization for high-volume log pipelines (filtering, sampling, tiered storage).
- Preferred experience with Splunk, ReliaQuest GreyMatter, or a comparable SIEM/data operations platform from a logging, ingestion, and pipeline-management perspective.
- Preferred experience supporting log-source integration during M&A or entity onboarding.
- Nice to have experience building compliance dashboards and reporting from log data.
- Nice to have relevant certifications (Splunk Certified Admin/Architect, GCDA, GCIA, GCTI, or equivalent).
Salary: 4510 - 6444 EUR gross monthly
# Li-hybrid
What Cencora offers
We offer a competitive annual bonus, life insurance from Day 1, a best-in-class health insurance package, and up to 6 fully paid benefit days a year. As a Cencora employee, you have the benefit of our referral bonus scheme, our boundless learning opportunities and our global Employee Assistance Program. We have a wonderful office location in Quadrum, equipped with everything you need for a small break at work and fresh snacks at all times. Become part of our purpose-driven, multicultural team now and help us create healthier futures
Full time
