
Security Monitoring Expert
Posted Sep 2

Posted Sep 2
This is a fully remote position, open to applicants in Germany.
• Conceptually design and implement a short-term security monitoring strategy for “Defending the Castle” within hybrid Azure and on-premise environments.
• Transform frontier-model-driven threat scenarios into detection logic, monitoring needs, telemetry deficiencies, alerting protocols, and escalation criteria.
• Collaborate with SOC, Cyber Defense Center, incident response, threat intelligence, cloud, identity, endpoint, and platform teams.
• Define and validate monitoring use cases for lateral movement, privilege escalation, identity misuse, cloud control-plane exploitation, data staging, exfiltration, and persistence.
• Develop playbooks, standard operating procedures (SOPs), tuning guidance, and practical runbooks for identifying, triaging, and escalating AI-assisted attacks.
• Establish measurable metrics for detection coverage, alert quality, and response readiness.
• Generate visibility into probable AI-accelerated attack vectors across identity, cloud, endpoint, network, and privileged-access layers.
• Optimize and technically assess telemetry, correlation, enrichment, and alert prioritization.
• Enhance early-warning capabilities prior to the initiation of the broader Business IT resilience program.
• Conduct technical peer reviews of detection logic across SOC, incident response, and platform functions.
• Implement and document Purple-team exercises and tabletop simulations, including generated alerts and escalation testing.
• Assemble an evidence pack that includes a detection catalog, data-source matrix, runbooks, tuning history, and open risk register.
• Prepare documentation for operational approval by the SOC lead, Cyber Defense lead, and Azure/on-premise service owners.
• Identify and perform technical analyses on gaps in existing processes and document potential optimizations.
• Convert risk assessments into actionable playbooks, technical control frameworks, testing protocols, backlog items, and management evidence.
• Provide a structured Phase 2 backlog and suggestions for the overarching Business IT resilience plan.
• Create detailed documentation and present results to Uniper for evaluation and approval.
• At least 8 years of experience in cyber defense operations, SOC engineering, detection engineering, threat hunting, or security monitoring.
• Strong knowledge of SIEM, XDR, EDR, Microsoft Sentinel, or comparable platforms.
• Proficient in KQL/SPL-style query languages and cloud/security telemetry.
• Solid understanding of Azure security monitoring, Entra ID, hybrid identity, endpoint telemetry, network logs, MITRE ATT&CK, and attack-chain analysis.
• Experience in developing operational runbooks, alert tuning procedures, and SOC quality metrics.
• Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP, or their equivalents are advantageous.
• Profiles must be submitted in English.
• Contract duration: 21.09.2026 – 31.03.2027.
• 40 hours/week.
• Remote work.
• Opportunity to contribute to an AI threat resilience response and broader Business IT resilience planning.
• Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP, or equivalent are beneficial.
SyncEzy
Thrive
Capgemini
Get handpicked remote jobs straight to your inbox weekly.