
Security Operations Engineer
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in Europe.
• Design, implement, and oversee essential defensive systems, security integrations, and infrastructure safeguards.
• Assess system architectures from an adversary's viewpoint, pinpoint attack surfaces, and develop defensive countermeasures.
• Evaluate new features and integration architectures for potential security vulnerabilities.
• Monitor vulnerability findings from scans, penetration tests, and bug reports, prioritize by risk, and ensure remediation is completed.
• Manage, configure, and maintain SIEM/SOAR platforms for threat detection and incident response.
• Craft, refine, and enhance detection queries and alerts.
• Analyze alerts, conduct forensic investigations, and oversee escalation and communication during active incidents.
• Generate reports for security assessments, threat models, and incident investigations.
• Confirm that security events, review outcomes, and remediation efforts are documented and accessible for audits and regulatory compliance.
• Remain informed on emerging threats, attack methodologies, and security engineering practices.
• Bachelor's degree in Computer Science, Cybersecurity, or a related discipline.
• 5–7+ years of practical experience in developing defensive security systems, applying security measures, or working in security response settings.
• Robust technical expertise in understanding attack strategies, conducting threat assessments, and leading incident response initiatives.
• Experience overseeing vulnerability findings from discovery through remediation.
• Proficient knowledge of SIEM/SOAR platforms and crafting detection rules (e.g., SPL, KQL, or similar).
• Comprehensive understanding of network, host, application, and cloud security principles.
• Excellent written and verbal communication abilities, with the skill to clearly document findings and escalate issues as necessary.
• Capability to work autonomously with minimal oversight in a fast-paced setting.
• Experience working with small, international teams across various time zones.
• Willingness to work outside standard business hours when required for incident response.
• Familiarity with threat modeling frameworks (e.g., STRIDE, MITRE ATT&CK).
• Experience in implementing automated security measures and infrastructure security tools.
• Practical experience with SIEM platforms at scale (Sumo Logic, Splunk, Azure Sentinel, Datadog, or analogous platforms).
• Knowledge of cloud security monitoring (AWS, Azure, GCP) and their native security services.
• Exposure to containerized environments (Docker, Kubernetes) and securing cloud-native applications.
• Familiarity with security and compliance standards (ISO 27001/2, NIST, SOC2, GDPR, DORA).
• Proficiency in at least one object-oriented programming language; Python is preferred.
• Experience with at least one query language such as KQL or a similar variant.
• Competitive salary and equity
• Comprehensive health coverage for you and your family
• Unlimited PTO
• Dedicated budget for courses, conferences, and certifications
• Remote-friendly approach
• Top-tier tools and equipment
Zscaler
Stripe
DeepHealth
DeepHealth
Get handpicked remote jobs straight to your inbox weekly.