Security Engineer – SOC

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security Engineer developing SOC detection systems for APT-ONE, a Berlin cybersecurity consultancy. Building SIEM/XDR platforms, detection-as-code pipelines, and AI-assisted security workflows.

Responsibilities:

  • Build, operate, and continuously enhance SOC platforms (SIEM, SOAR, EDR/XDR)
  • Onboard new log sources, including parsing, normalization, and ensuring data quality
  • Develop and optimize detection rules and use cases with Sigma, KQL, and SPL based on MITRE ATT&CK
  • Automate analysis and response processes through playbooks and scripting with Python and PowerShell
  • Build detection-as-code pipelines, including version control, testing, and CI/CD
  • Integrate and operationalize threat intelligence
  • Work closely with analysts and incident responders to reduce false positives and improve detection quality
  • Provide technical support during security incidents
  • Create runbooks, use-case documentation, and technical concepts
  • Use AI-powered tools for log analysis, drafting rules and playbooks, and documentation, including expert validation and approval of the results

Requirements:

  • Confidently use AI tools in day-to-day consulting work, including critically evaluating their results
  • Demonstrate a strong awareness of confidentiality when using AI; understand the risks of data leakage, model training, and prompt injection
  • Willingness to continuously enhance processes and products using AI
  • At least 5 years of experience in IT/cybersecurity, including several years in architecture or consulting roles
  • Broad understanding of technologies across networking, endpoints, identity, applications, and cloud
  • Experience with Zero Trust and segmentation concepts, as well as IAM/PAM (Entra ID, Active Directory)
  • Proficiency with ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, and SABSA/TOGAF
  • Knowledge of cryptography, PKI, and secure application design
  • Fluent German and English, both written and spoken
  • Strong advantage: Cloud architecture expertise in Azure, AWS, GCP, cloud-native security services, and infrastructure as code
  • Strong advantage: Experience with prompt engineering, AI agents, or integrating LLMs into workflows
  • Strong advantage: Knowledge of AI governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM Applications)
  • Strong advantage: Experience in regulated environments (critical infrastructure, financial services, industry/OT)
  • Certifications are a plus: OffSec, OSDA, OSCP, SANS/GIAC, GCDA, GDSA, GCIH, SANS SEC586, and Microsoft SC-200

Benefits:

  • Base salary from €80,000 plus profit sharing of up to €70,000
  • Flexible working hours
  • Remote work
  • 30 days of vacation
  • IT equipment, such as an Apple MacBook
  • Regular team events
  • Company pension plan
  • Health insurance
  • Shopping and employee discounts