Security Engineer – SOC
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security Engineer developing SOC detection systems for APT-ONE, a Berlin cybersecurity consultancy. Building SIEM/XDR platforms, detection-as-code pipelines, and AI-assisted security workflows.
Responsibilities:
- Build, operate, and continuously enhance SOC platforms (SIEM, SOAR, EDR/XDR)
- Onboard new log sources, including parsing, normalization, and ensuring data quality
- Develop and optimize detection rules and use cases with Sigma, KQL, and SPL based on MITRE ATT&CK
- Automate analysis and response processes through playbooks and scripting with Python and PowerShell
- Build detection-as-code pipelines, including version control, testing, and CI/CD
- Integrate and operationalize threat intelligence
- Work closely with analysts and incident responders to reduce false positives and improve detection quality
- Provide technical support during security incidents
- Create runbooks, use-case documentation, and technical concepts
- Use AI-powered tools for log analysis, drafting rules and playbooks, and documentation, including expert validation and approval of the results
Requirements:
- Confidently use AI tools in day-to-day consulting work, including critically evaluating their results
- Demonstrate a strong awareness of confidentiality when using AI; understand the risks of data leakage, model training, and prompt injection
- Willingness to continuously enhance processes and products using AI
- At least 5 years of experience in IT/cybersecurity, including several years in architecture or consulting roles
- Broad understanding of technologies across networking, endpoints, identity, applications, and cloud
- Experience with Zero Trust and segmentation concepts, as well as IAM/PAM (Entra ID, Active Directory)
- Proficiency with ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, and SABSA/TOGAF
- Knowledge of cryptography, PKI, and secure application design
- Fluent German and English, both written and spoken
- Strong advantage: Cloud architecture expertise in Azure, AWS, GCP, cloud-native security services, and infrastructure as code
- Strong advantage: Experience with prompt engineering, AI agents, or integrating LLMs into workflows
- Strong advantage: Knowledge of AI governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM Applications)
- Strong advantage: Experience in regulated environments (critical infrastructure, financial services, industry/OT)
- Certifications are a plus: OffSec, OSDA, OSCP, SANS/GIAC, GCDA, GDSA, GCIH, SANS SEC586, and Microsoft SC-200
Benefits:
- Base salary from €80,000 plus profit sharing of up to €70,000
- Flexible working hours
- Remote work
- 30 days of vacation
- IT equipment, such as an Apple MacBook
- Regular team events
- Company pension plan
- Health insurance
- Shopping and employee discounts



















