Security Monitoring Expert

Job not on LinkedIn

🕒 4 days ago

🇩🇪 Germany – Remote

⏳ Contract/Temporary

🟠 Senior

🔴 Lead

🛡️ Security Operations

👻 Ghost score 25%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of C4 Group

C4 Group

11 - 50 employees

Founded 2008

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

C4 Group is an IT and management consulting firm that provides recruitment, project and interim management, M&A and post-merger-integration, DevOps & cloud operations, business intelligence and data analytics, SAP/S4 migration, and security & infrastructure services. Founded in 2008, it works primarily with energy, pharmaceutical/life-sciences, and financial-services clients to deliver tailored business, IT and M&A solutions, leveraging strategic partnerships and a consultant network to implement digital transformation projects including AI/ML, RPA, predictive maintenance and energy-optimization use cases.

📋 Description

• Conceptually develop and structurally implement a short-term security monitoring strategy for “Defending the Castle” across hybrid Azure and on-premise environments • Translate frontier-model-driven threat scenarios into detection logic, monitoring requirements, telemetry gaps, alerting rules and escalation criteria • Consult with SOC, Cyber Defense Center, incident response, threat intelligence, cloud, identity, endpoint and platform teams • Define and validate monitoring use cases for lateral movement, privilege escalation, identity abuse, cloud control-plane abuse, data staging, exfiltration and persistence • Produce playbooks, SOPs, tuning guidance and practical runbooks for detecting, triaging and escalating AI-assisted attacks • Establish measurable detection coverage, alert quality and response-readiness metrics • Create visibility into likely AI-accelerated attack paths across identity, cloud, endpoint, network and privileged-access layers • Optimize and technically evaluate telemetry, correlation, enrichment and alert prioritization • Strengthen early-warning capability before the broader Business IT resilience programme launches • Conduct technical peer reviews of detection logic across SOC, incident response and platform functions • Execute and document Purple-team exercises and tabletop scenarios, including simulated alert generation and escalation testing • Compile an evidence pack with detection catalog, data-source matrix, runbooks, tuning history and open risk register • Prepare documentation for operational sign-off by SOC lead, Cyber Defense lead and Azure/on-premise service owners • Identify and technically analyze gaps in existing processes and document optimization potential • Transform risk evaluations into executable playbooks, technical control frameworks, test protocols, backlog items and management evidence • Provide a structured Phase 2 backlog and recommendations for the broader Business IT resilience plan • Create comprehensive documentation and hand over results to Uniper for review and approval

🎯 Requirements

• Minimum 8 years in cyber defense operations, SOC engineering, detection engineering, threat hunting or security monitoring • Strong expertise in SIEM, XDR, EDR, Microsoft Sentinel or equivalent platforms • Proficiency in KQL/SPL-style query languages and cloud/security telemetry • Good understanding of Azure security monitoring, Entra ID, hybrid identity, endpoint telemetry, network logs, MITRE ATT&CK and attack-chain analysis • Experience creating operational runbooks, alert tuning processes and SOC quality metrics • Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP or equivalent are beneficial • Profiles must be submitted in English

🏖️ Benefits

• Contract duration: 21.09.2026 – 31.03.2027 • 40 hours/week • Remote work • Opportunity to contribute to an AI threat resilience response and broader Business IT resilience planning • Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP or equivalent are beneficial

Apply Now