Security Operations Engineer

Posted 2 days ago

This is a fully remote position, open to applicants in Europe.

📋 Description

• Design and develop SecOps tools as part of the larger security tool ecosystem.

• Create architectural patterns and solution designs for SIEM, SOAR, vulnerability detection and management, EDR, logging pipelines, and user behavior analytics.

• Assess and incorporate new tools and platforms to enhance detection, response, and automation capabilities.

• Construct and sustain scalable data ingestion, correlation, and alerting workflows.

• Automate repetitive security operations tasks through the use of playbooks, scripts, and workflows.

• Contribute to the establishment of a structured 24x7 security operations capability.

• Offer technical support during incidents, emphasizing tooling, data quality, and engineering solutions.

• Enhance detection content, correlation rules, dashboards, and data models based on actual incident patterns.

• Assist with rapid instrumentation, log onboarding, and custom tooling during active security incidents.

• Develop, test, and operationalize new detection capabilities in response to evolving threats and platform telemetry.

• Create and maintain detection-as-code artifacts, such as Sigma, YARA, KQL, and static analysis rules.

• Validate detection quality through adversary simulation and purple teaming exercises.

• Ensure rules are documented, version-controlled, and validated against production data.


⛳️ Requirements

• Over 5 years of experience in security operations, engineering, and cloud security tools.

• Practical experience with SIEM/SOAR, EDR platforms, log ingestion, and telemetry pipelines.

• Proficient in scripting (Python, PowerShell, or Go).

• Experience with infrastructure-as-code, CI/CD toolchains, and Kubernetes.

• Knowledge of threat modeling, detection engineering frameworks, TTP matrices, and MITRE ATT&CK.

• Experience in creating architectural diagrams, interface specifications, and onboarding documentation.

• Familiarity with logging and detection for cloud architectures.

• Fluent in English (C1 or higher).

• Experience with Wazuh.

• Familiar with observability platforms / OpenTelemetry.

• Background as a SOC Analyst (Tier 1–3) or strong understanding of SOC operations.

• Knowledge of security frameworks (BSI, ISO 27001, MITRE ATT&CK, etc.).

• Experience with GCP or another public cloud provider.

• DFIR / blue team certifications (CySA+, GIAC, GCIH, BTL).

• Kubernetes security certification (CKS or CNCF-related).


🏝️ Benefits

• Competitive salary and performance-based bonuses.

• Opportunities for professional development and career advancement.

• Comprehensive health and wellness benefits.

• Flexible work arrangements and a supportive team environment.

People also viewed

Gcore23 hours ago

SOC Analyst – WAAP

PL flagPoland, +1 more countryFull-timeSecurity Operations
ApplyView job
UltraViolet Cyber1 day ago

Senior SOC Analyst – MDR

US flagUnited States OnlyFull-timeSecurity Operations
ApplyView job
Commit1 day ago

SOC Analyst

MX flagMexico OnlyFull-timeSecurity Operations
ApplyView job
Commit1 day ago

SOC Analyst

MX flagMexico OnlyFull-timeSecurity Operations
ApplyView job
Commit2 days ago

SOC Analyst

PH flagPhilippines OnlyFull-timeSecurity Operations
ApplyView job
THEOS Cyber2 days ago

DFIR Specialist – Senior SOC Analyst

HK flagHong Kong, +3 more countriesFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers