
Security Engineer – SOC
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in Germany.
• Design, manage, and continually improve SOC platforms (SIEM, SOAR, EDR/XDR)
• Integrate new log sources, which includes parsing, normalization, and ensuring data integrity
• Create and refine detection rules and use cases utilizing Sigma, KQL, and SPL aligned with MITRE ATT&CK
• Automate analysis and response workflows through playbooks and scripting in Python and PowerShell
• Develop detection-as-code pipelines, incorporating version control, testing, and CI/CD practices
• Incorporate and operationalize threat intelligence
• Collaborate closely with analysts and incident responders to minimize false positives and enhance detection accuracy
• Offer technical assistance during security incidents
• Produce runbooks, use-case documentation, and technical specifications
• Leverage AI-driven tools for log analysis, rule drafting, playbook creation, and documentation, including expert validation and approval of outcomes
• Proficiently utilize AI tools in daily consulting tasks, including critically assessing their outcomes
• Exhibit a strong understanding of confidentiality when employing AI; be aware of the risks related to data leakage, model training, and prompt injection
• Eagerness to continually improve processes and products through AI integration
• Minimum of 5 years of experience in IT/cybersecurity, with several years spent in architecture or consulting positions
• Comprehensive knowledge of technologies encompassing networking, endpoints, identity, applications, and cloud
• Familiarity with Zero Trust and segmentation principles, as well as IAM/PAM (Entra ID, Active Directory)
• Expertise in ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, and SABSA/TOGAF frameworks
• Understanding of cryptography, PKI, and secure application development
• Fluent in both German and English, written and spoken
• Strong advantage: Expertise in cloud architecture within Azure, AWS, GCP, cloud-native security services, and infrastructure as code
• Strong advantage: Experience in prompt engineering, AI agents, or the integration of LLMs into workflows
• Strong advantage: Knowledge of AI governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM Applications)
• Strong advantage: Experience in regulated environments (critical infrastructure, financial services, industry/OT)
• Certifications are beneficial: OffSec, OSDA, OSCP, SANS/GIAC, GCDA, GDSA, GCIH, SANS SEC586, and Microsoft SC-200
• Base salary starting at €80,000 with profit sharing of up to €70,000
• Flexible working hours
• Options for remote work
• 30 days of vacation
• IT equipment provided, such as an Apple MacBook
• Regular team-building events
• Company pension scheme
• Health insurance coverage
• Employee discounts and shopping benefits
SyncEzy
Thrive
Capgemini
Get handpicked remote jobs straight to your inbox weekly.