Security Monitoring Expert

Posted Sep 2

This is a fully remote position, open to applicants in Germany.

📋 Description

• Conceptually design and implement a short-term security monitoring strategy for “Defending the Castle” within hybrid Azure and on-premise environments.

• Transform frontier-model-driven threat scenarios into detection logic, monitoring needs, telemetry deficiencies, alerting protocols, and escalation criteria.

• Collaborate with SOC, Cyber Defense Center, incident response, threat intelligence, cloud, identity, endpoint, and platform teams.

• Define and validate monitoring use cases for lateral movement, privilege escalation, identity misuse, cloud control-plane exploitation, data staging, exfiltration, and persistence.

• Develop playbooks, standard operating procedures (SOPs), tuning guidance, and practical runbooks for identifying, triaging, and escalating AI-assisted attacks.

• Establish measurable metrics for detection coverage, alert quality, and response readiness.

• Generate visibility into probable AI-accelerated attack vectors across identity, cloud, endpoint, network, and privileged-access layers.

• Optimize and technically assess telemetry, correlation, enrichment, and alert prioritization.

• Enhance early-warning capabilities prior to the initiation of the broader Business IT resilience program.

• Conduct technical peer reviews of detection logic across SOC, incident response, and platform functions.

• Implement and document Purple-team exercises and tabletop simulations, including generated alerts and escalation testing.

• Assemble an evidence pack that includes a detection catalog, data-source matrix, runbooks, tuning history, and open risk register.

• Prepare documentation for operational approval by the SOC lead, Cyber Defense lead, and Azure/on-premise service owners.

• Identify and perform technical analyses on gaps in existing processes and document potential optimizations.

• Convert risk assessments into actionable playbooks, technical control frameworks, testing protocols, backlog items, and management evidence.

• Provide a structured Phase 2 backlog and suggestions for the overarching Business IT resilience plan.

• Create detailed documentation and present results to Uniper for evaluation and approval.


⛳️ Requirements

• At least 8 years of experience in cyber defense operations, SOC engineering, detection engineering, threat hunting, or security monitoring.

• Strong knowledge of SIEM, XDR, EDR, Microsoft Sentinel, or comparable platforms.

• Proficient in KQL/SPL-style query languages and cloud/security telemetry.

• Solid understanding of Azure security monitoring, Entra ID, hybrid identity, endpoint telemetry, network logs, MITRE ATT&CK, and attack-chain analysis.

• Experience in developing operational runbooks, alert tuning procedures, and SOC quality metrics.

• Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP, or their equivalents are advantageous.

• Profiles must be submitted in English.


🏝️ Benefits

• Contract duration: 21.09.2026 – 31.03.2027.

• 40 hours/week.

• Remote work.

• Opportunity to contribute to an AI threat resilience response and broader Business IT resilience planning.

• Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP, or equivalent are beneficial.

People also viewed

SyncEzy1 day ago

SOC Analyst

Anywhere in the WorldFull-timeSecurity Operations₹700k – ₹900k/year
ApplyView job
Thrive1 day ago

Director, Security Operations Center

US flagFlorida OnlyFull-timeSecurity Operations
ApplyView job
Capgemini2 days ago

SOC Analyst Internship

FR flagFrance OnlyInternshipSecurity Operations
ApplyView job
Capgemini2 days ago

SOC Analyst – Internship

FR flagFrance OnlyInternshipSecurity Operations
ApplyView job
LEADtech2 days ago

SOC Analyst

ES flagSpain OnlyFull-timeSecurity Operations
ApplyView job
Teamified2 days ago

Security Operations Engineer – PCI DSS

LK flagSri Lanka OnlyFreelanceSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers