Cybersecurity Monitoring Lead

Employer: Siemens Energy
Domain:
  • Internet - eCommerce
  • IT Hardware
  • IT Software
  • Job type:: full-time
    Job level: 1 - 5 ani experienta
    Location:
  • BUCURESTI
  • Updated at: 09-09-2026
    Remote work: On-site

    A Snapshot of Your Day

    Join us as the SOC Lead for our new Security Operations Center in Bucharest, where you will stand up and lead security monitoring and incident response for the HVDC/FACTS stations we service across Grid Technologies' existing projects. Imagine leading a team of analysts on the front line, monitoring, detecting, and responding to threats across both enterprise IT and industrial (OT) environments ??? from servers, endpoints, and networks through to the ICS, PLCs, DCS, and SCADA systems that keep HVDC and FACTS stations running. You will shape the operating model of a greenfield SOC, define how it runs day to day, and act as the bridge between SOC operations, OT engineering, and incident response teams, ensuring incidents are caught early and managed effectively while preserving operational continuity and safety. Your leadership will be vital in building resilience, maturing detection capabilities, and growing the team.

    How You'll Make an Impact

    • Lead the establishment and day-to-day operations of a new SOC in the Bucharest office, covering both IT and OT security monitoring for HVDC stations across Grid Technologies Service engagements.
    • Build, mentor, and manage a team of SOC analysts, defining roles, shift models, on-call rotations, and career development paths while fostering a culture of continuous improvement.
    • Define and own the SOC operating model, processes, use cases, playbooks, and escalation procedures, ensuring coverage across enterprise IT (the majority of scope) and specialized OT/ICS environments.
    • Serve as the escalation point and senior decision-maker for security incidents, coordinating triage, investigation, containment, and recovery across IT and OT teams.
    • Direct the design and optimization of detection strategies across SIEM (Splunk), EDR/XDR, NDR, and specialized OT/ICS monitoring technologies to maximize visibility across hybrid environments.
    • Oversee the development, validation, and continuous enhancement of detection content - correlation rules, analytics, threat hunting methodologies, and response playbooks - for both IT and industrial threats.
    • Lead incident response planning and major incident investigations, providing guidance on containment strategies and recommendations for long-term risk reduction while balancing cybersecurity, operational, and safety requirements.
    • Establish monitoring baselines, maturity metrics, KPIs, and SLAs for SOC operations, and report on SOC performance, risk posture, and improvement initiatives to management and stakeholders.
    • Own stakeholder relationships across cybersecurity, OT engineering, automation, IT, and client-facing Service teams, translating security needs into actionable operational capabilities.
    • Contribute to security strategy, technology evaluations, tooling decisions, and roadmap development, helping shape the organization's detection and response capabilities.
    • Ensure SOC operations align with relevant frameworks and regulations, including IEC 62443, NIST CSF, ISO 27001, and NIS2.

    What You Bring

    • 5+ years of cybersecurity experience, including significant hands-on experience in Security Operations Centers (SOC), Incident Response, Detection Engineering, or Threat Hunting, with at least 2-3 years in a lead or team management capacity.
    • Proven experience building, standing up, or operationalizing SOC capabilities, ideally spanning both enterprise IT and OT/industrial or critical infrastructure environments (energy, utilities, grid, or similar).
    • Strong IT security foundation, including endpoint, network, identity, and infrastructure security, with the ability to lead detection and response across a broad enterprise attack surface (the primary focus of the role).
    • Solid understanding of ICS/OT architectures and industrial processes, including working knowledge of PLC, HMI, SCADA, DCS, and industrial networking - experience with HVDC/FACTS, power transmission, or grid environments is a strong advantage.
    • Familiarity with industrial communication protocols such as Modbus, PROFINET, DNP3, IEC 60870-5-104, OPC UA, and EtherNet/IP.
    • Advanced knowledge of SIEM, EDR/XDR, NDR, and security monitoring technologies, including use case development, correlation rule creation, and detection tuning. Hands-on experience with Splunk is strongly preferred, as it will be the primary SIEM platform.
    • Experience leading incident response activities, investigations, and forensic analysis while balancing cybersecurity objectives with operational and safety requirements.
    • Strong understanding of cybersecurity frameworks and standards, including IEC 62443, NIST CSF, ISO 27001, NIS2, and relevant industry regulations.
    • Demonstrated people-leadership skills: building teams, mentoring analysts, driving SOC maturity, and leading process improvement and knowledge development initiatives.
    • Excellent stakeholder management and communication skills, with the ability to work effectively across cybersecurity, engineering, automation, operations, and client-facing teams.
    • Ability to translate threat intelligence into actionable detection and response capabilities across both IT and industrial environments.
    • Fluent English; German is a plus. Willingness to travel internationally on occasion.

    About the Team

    Our Grid Technology division enables a reliable, sustainable, and digital grid. Siemens Energy offers an outstanding range and solutions in HVDC transmission, grid stabilization and storage, high voltage switchgears and transformers, and technology related to digital grid technology.

    Who is Siemens Energy?

    At Siemens Energy, we are more than just an energy technology company. We meet the growing energy demand across 90+ countries while ensuring our climate is protected. With 100,000 dedicated employees, we not only generate electricity for over 16% of the global community, but we're also using our technology to help protect people and the environment.

    Our cross-border team is committed to making sustainable, reliable, and affordable energy a reality by pushing the boundaries of what is possible. We uphold a 150-year legacy of innovation that encourages our search for people who will support our focus on decarbonization, new technologies, and energy transformation.

    Find out how you can make a difference at Siemens Energy: https://www.siemens-energy.com/employeevideo

    Our Office

    Siemens Energy's location in One Cotroceni Park is more than just an office space - it's a hub for a vibrant and growing community. Nestled in the heart of Bucharest, this urban development is the perfect place to work, surrounded by green spaces, shopping destinations, and everything the city center has to offer. And with the Academia Militara subway station just a 3-minute walk away, getting around the city has never been easier.

    Our Commitment to Diversity

    Lucky for us, we are not all the same. Through diversity, we generate power. We run on inclusion and our combined creative energy is motivated by over 130 nationalities. Siemens Energy celebrates character ??? no matter what ethnic background, gender, age, religion, identity, or disability. We energize society, all of society, and we do not discriminate based on our differences.

    Rewards/ Benefits

    • Your lunch with SE meal tickets
    • Keep your brain fit with our trainings
    • Special for books lovers - Bookster
    • Stay safe and healthy with our medical subscription
    • Think about your future too with Private Pension Pilon III
    • Look after yourself with our Wellbeing Initiatives

    #LI-CG1

    #LI-Hybrid



    Job-uri similare care te-ar putea interesa:

    IT/OT L2 Cybersecurity Monitoring Specialist

    BUCURESTI,

    Industrial Cybersecurity Risk Analyst

    BUCURESTI,

    Senior Full-Stack Developer / Technical Lead

    Hybrid

    Vezi job-uri similare ( 269 )