← Toutes les offres

Security Engineer – SOC

À propos du poste

• Build, operate, and continuously enhance SOC platforms (SIEM, SOAR, EDR/XDR)
• Onboard new log sources, including parsing, normalization, and ensuring data quality
• Develop and optimize detection rules and use cases with Sigma, KQL, and SPL based on MITRE ATT&CK
• Automate analysis and response processes through playbooks and scripting with Python and PowerShell
• Build detection-as-code pipelines, including version control, testing, and CI/CD
• Integrate and operationalize threat intelligence
• Work closely with analysts and incident responders to reduce false positives and improve detection quality
• Provide technical support during security incidents
• Create runbooks, use-case documentation, and technical concepts
• Use AI-powered tools for log analysis, drafting rules and playbooks, and documentation, including expert validation and approval of the results

• Confidently use AI tools in day-to-day consulting work, including critically evaluating their results
• Demonstrate a strong awareness of confidentiality when using AI; understand the risks of data leakage, model training, and prompt injection
• Willingness to continuously enhance processes and products using AI
• At least 5 years of experience in IT/cybersecurity, including several years in architecture or consulting roles
• Broad understanding of technologies across networking, endpoints, identity, applications, and cloud
• Experience with Zero Trust and segmentation concepts, as well as IAM/PAM (Entra ID, Active Directory)
• Proficiency with ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, and SABSA/TOGAF
• Knowledge of cryptography, PKI, and secure application design
• Fluent German and English, both written and spoken
• Strong advantage: Cloud architecture expertise in Azure, AWS, GCP, cloud-native security services, and infrastructure as code
• Strong advantage: Experience with prompt engineering, AI agents, or integrating LLMs into workflows
• Strong advantage: Knowledge of AI governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM Applications)
• Strong advantage: Experience in regulated environments (critical infrastructure, financial services, industry/OT)
• Certifications are a plus: OffSec, OSDA, OSCP, SANS/GIAC, GCDA, GDSA, GCIH, SANS SEC586, and Microsoft SC-200

• Base salary from €80,000 plus profit sharing of up to €70,000
• Flexible working hours
• Remote work
• 30 days of vacation
• IT equipment, such as an Apple MacBook
• Regular team events
• Company pension plan
• Health insurance
• Shopping and employee discounts