Platform Engineer - Monitoring, Observability & SIEM (MONSO)
Joh. Berenberg, Gossler & Co. KG
Job at a glance
Vereinigtes Königreich Stadt London Art der Anstellung Professional Arbeitszeit Vollzeit Vertragsart Unbefristet Offene Stellen 1Beschreibung & Anforderungen For our SPEAR Technology (Security, Platform Engineering, Automation and Runtime) division in London we are looking to hire a: Platform Engineer - Monitoring, Observability & SIEM (MONSO) Do you: Like solving puzzles with an inquisitive mind?
Think outside the box and challenge the status quo? Prefer simplicity over complexity and automation over manual effort? Have a self-starter mindset with a drive to take proactive ownership? Then consider joining Berenberg's SPEAR Technology programme. SPEAR consists of our CyberSecurity team and several platform engineering teams responsible for Monitoring, Observability, Kubernetes, Developer Platform, Network, and Datacentre Infrastructure.
Due to each team's compact size, all team members are subject matter experts offering an excellent environment to learn continuously, share unique skills, and make a noticeable, impactful contribution across the bank. Your role in the team The MONSO (Monitoring and Security Operations) platform team is evolving towards a modern platform engineering and self-service model. Rather than handling manual operational requests, our focus is building "as-code" platforms and automations that enable other teams to do more themselves-such as empower-ing our SOC/CyberSec team to develop (including AI-assisted workflows), test, and deploy SIEM use cases independently via CI/CD.
The platform spans Splunk Enterprise on-prem (running on Kubernetes), Splunk Observability Cloud, and SolarWinds, with future expansion into Cisco Secure Network Analytics, Cisco XDR, and Rapid7. What will you do? Build and maintain our monitoring, observability, and SIEM tooling using modern platform engineering practices (Infrastructure/Configuration as Code). Deploy, scale, and automate platform workloads (including Splunk and custom automations) on our internal Kubernetes platform.
Develop pipelines and self-service automations that allow the CyberSec/SOC team and developers to onboard data and deploy detection use cases autonomously. Ensure robust integration across hybrid infrastructure, log pipelines, and network telemetry. Self-Starter & DevOps Mindset: Proactive problem solver who champions automation-first, CI/CD pipelines, code reviews, and self-service enablement.
Modern Observability & Telemetry: Strong background in Splunk (SPL, dashboards, alerts, data ingestion, forwarders) and also configuring OpenTelemetry collectors and pipelines; knowledge of Prometheus and Grafana or similar tools. Kubernetes (Power User): Strong, hands-on experience deploying and operating workloads, stateful appli-cations, Helm charts, and manifests on K8s (cluster administration is managed by a dedicated team).
Good Networking Knowledge: Firm grasp of networking fundamentals (TCP/IP, DNS, TLS, load balancing, firewalls) and network telemetry (NetFlow/IPFIX, SNMP, syslog). Scripting & Automation: Strong proficiency in Python and Linux/Bash scripting to build integrations, CLI tools, and automated pipelines. Linux: Confident with enterprise Linux administration, troubleshooting, and system performance.
Desirable: Splunk administration, Splunk on Kubernetes (Splunk Operator), Enterprise Security (ES), or ITSI. Familiarity with network security/XDR tooling (Cisco Secure Network Analytics / Stealthwatch, Cisco XDR, Rapid7). Experience with CI/CD tooling (GitLab CI, GitHub Actions) and GitOps practices. Exposure to automated or AI-assisted SIEM detection engineering and SOAR concepts. Incident and Capacity Management understanding.
We are a leading European private bank, with over 430 years of experience and deep rooted history, but we are still shaping and heavily investing in our future. Our progress and evolution are driven by our people. We encourage them to try new approaches, voice their opinions and achieve success in their own way. We provi