{"id":1159353,"url":"https://alion.io/job/cencora-senior-cyber-security-engineer-siem","title":"Senior Cyber Security Engineer (SIEM)","company":{"id":1040788,"name":"Cencora","domain":"cencora.com","url":"https://alion.io/company/cencora","size_band":"5000+","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Vilnius, Lithuania"],"countries":["LT"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":54000,"max_usd":121000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1098},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"IAM","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false}],"status":"live","first_seen_at":"2026-09-23T22:58:28Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-24T19:06:07Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Cencora, previously known as AmerisourceBergen, is a leading global pharmaceutical solutions organization centered on improving lives. Ranked #21 on the Global Fortune 500, our team members are united in our responsibility to create healthier futures.\nOur Shared Service Center in Lithuania is experiencing rapid growth and we have many diverse and exciting roles in Customer Service, Operations, IT, Finance and HR. Join us and make a positive impact on human and animal health.\nJob Details\nHands-on engineering role focused on the security data pipeline that supports enterprise logging, monitoring, analytics, compliance, and downstream detection needs. Onboards, parses, normalizes, enriches, and routes log and telemetry data into the SIEM, data lake, and archival platforms. This is a full individual-contributor role for an engineer who wants ownership of the end-to-end path from raw log source to trusted, usable security data. \n\nResponsibilities:\nOnboard assigned security and operational log sources - endpoints, workstations, servers, network devices, and cloud services - into the centralized logging pipeline using established standards and patterns. \nParse, normalize, and validate incoming data to improve consistency, schema alignment, and usability for downstream analysis and correlation. \nConfigure and maintain approved data routing logic to support delivery to destinations such as the SIEM, data lake, archival storage, and other authorized platforms. \nApply established categorization logic to help distinguish security-relevant data from non-security or operational data and support cost and signal-to-noise optimization. \nOperate and support the data pipeline platform (Databahn or equivalent) for centralized log collection, monitoring support, and reliable security data delivery at scale. \nSupport UEBA use cases by ensuring assigned identity, endpoint, and behavioral data sources are collected, enriched, and available for behavioral analytics on users and systems. \nBuild and maintain assigned compliance reporting and dashboards using available log data to support audit, regulatory, and operational reporting needs. \nSupport logging integration for M&A or entity onboarding activities by implementing assigned log-source onboarding, validation, and issue-resolution tasks against defined timelines. \nSupport SIEM log aggregation and correlation needs by ensuring assigned sources are onboarded, parsed, enriched, and available for detection and monitoring use cases. \nContribute to team knowledge sharing by documenting onboarding patterns, troubleshooting steps, parser logic, and operational procedures for repeatable execution. \nWork Experience:\n4-6 years in security engineering, SIEM engineering, or security data pipeline engineering, with demonstrable hands-on delivery in log onboarding, parsing, normalization, enrichment, routing, or pipeline operations. \nHands-on Splunk engineering experience covering data onboarding, parsing, field extraction, source-type design, ingestion health, and data-quality troubleshooting. \nPractical experience with a log pipeline/data routing platform (Databahn, Cribl, or comparable) for ingestion, parsing, normalization, and multi-destination routing. \nWorking knowledge of endpoint, network, cloud, and identity/IAM telemetry, including the parsing, normalization, enrichment, and routing challenges each presents. \nScripting and automation skills (Python or similar) applied to parser development, data-quality checks, enrichment workflows, pipeline testing, or operational automation. \nSkills and Knowledge:\nPreferred experience integrating log data into a data lake/lakehouse platform for large-scale storage and analytics.\nPreferred exposure to behavioral analytics data requirements, including the identity, endpoint, and activity telemetry needed to support them.\nNice to have familiarity with cost/volume optimization for high-volume log pipelines (filtering, sampling, tiered storage).\nPreferred experience with Splunk, ReliaQuest GreyMatter, or a comparable SIEM/data operations platform from a logging, ingestion, and pipeline-management perspective.\nPreferred experience supporting log-source integration during M&A or entity onboarding.\nNice to have experience building compliance dashboards and reporting from log data.\nNice to have relevant certifications (Splunk Certified Admin/Architect, GCDA, GCIA, GCTI, or equivalent).\nSalary: 4510 - 6444 EUR gross monthly\n# Li-hybrid\nWhat Cencora offers\nWe offer a competitive annual bonus, life insurance from Day 1, a best-in-class health insurance package, and up to 6 fully paid benefit days a year. As a Cencora employee, you have the benefit of our referral bonus scheme, our boundless learning opportunities and our global Employee Assistance Program. We have a wonderful office location in Quadrum, equipped with everything you need for a small break at work and fresh snacks at all times. Become part of our purpose-driven, multicultural team now and help us create healthier futures\nFull timeAffiliated Companies:\nAffiliated Companies: World Courier (Lithuania) UAB","description_format":"text","description_chars":5110,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Health insurance","Life insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Security Operations","Cell & Gene Therapy"],"lifecycle":[{"event":"open","at":"2026-09-23T22:58:28Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":22,"reasons":["conf:2","win:early","comp:brand"],"computed_at":"2026-09-24T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/cencora-senior-cyber-security-engineer-siem","json_url":"https://alion.io/job/cencora-senior-cyber-security-engineer-siem.json","meta":{"generated_at":"2026-09-24T23:23:10Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1585,"day_limit":5000,"remaining_today":3415,"minute_limit":60,"resets_at":"2026-09-25T00:00:00Z"}}}