
Security Operations Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Europe.
• Design and develop SecOps tools as part of the larger security tool ecosystem.
• Create architectural patterns and solution designs for SIEM, SOAR, vulnerability detection and management, EDR, logging pipelines, and user behavior analytics.
• Assess and incorporate new tools and platforms to enhance detection, response, and automation capabilities.
• Construct and sustain scalable data ingestion, correlation, and alerting workflows.
• Automate repetitive security operations tasks through the use of playbooks, scripts, and workflows.
• Contribute to the establishment of a structured 24x7 security operations capability.
• Offer technical support during incidents, emphasizing tooling, data quality, and engineering solutions.
• Enhance detection content, correlation rules, dashboards, and data models based on actual incident patterns.
• Assist with rapid instrumentation, log onboarding, and custom tooling during active security incidents.
• Develop, test, and operationalize new detection capabilities in response to evolving threats and platform telemetry.
• Create and maintain detection-as-code artifacts, such as Sigma, YARA, KQL, and static analysis rules.
• Validate detection quality through adversary simulation and purple teaming exercises.
• Ensure rules are documented, version-controlled, and validated against production data.
• Over 5 years of experience in security operations, engineering, and cloud security tools.
• Practical experience with SIEM/SOAR, EDR platforms, log ingestion, and telemetry pipelines.
• Proficient in scripting (Python, PowerShell, or Go).
• Experience with infrastructure-as-code, CI/CD toolchains, and Kubernetes.
• Knowledge of threat modeling, detection engineering frameworks, TTP matrices, and MITRE ATT&CK.
• Experience in creating architectural diagrams, interface specifications, and onboarding documentation.
• Familiarity with logging and detection for cloud architectures.
• Fluent in English (C1 or higher).
• Experience with Wazuh.
• Familiar with observability platforms / OpenTelemetry.
• Background as a SOC Analyst (Tier 1–3) or strong understanding of SOC operations.
• Knowledge of security frameworks (BSI, ISO 27001, MITRE ATT&CK, etc.).
• Experience with GCP or another public cloud provider.
• DFIR / blue team certifications (CySA+, GIAC, GCIH, BTL).
• Kubernetes security certification (CKS or CNCF-related).
• Competitive salary and performance-based bonuses.
• Opportunities for professional development and career advancement.
• Comprehensive health and wellness benefits.
• Flexible work arrangements and a supportive team environment.
Gcore
UltraViolet Cyber
Get handpicked remote jobs straight to your inbox weekly.