Security Operations Engineer

Likely ghost job

🕒 May 23

🇩🇪 Germany – Remote

⏳ Contract/Temporary

🟡 Mid-level

🟠 Senior

🛡️ Security Operations

👻 Ghost score 75%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Interval Group

Interval Group

51 - 200 employees

📣 Marketing

⚖️ Legal

📦 Logistics

Marketing • Legal • Logistics

Interval Group is a boutique consulting and recruitment firm specializing in providing expert resources to help industry-leading organizations achieve their goals. With a global talent network of over 20 million professionals, Interval Group focuses on hiring exceptional talent for various roles including permanent, contract, and freelance positions. Their team of specialists is chosen for their expertise in areas such as technology, strategy, education, financial services, and corporate functions, ensuring the right professionals deliver effective solutions tailored to client needs. Founded by seasoned consultants, Interval Group emphasizes quality over size, aiming to be the best in their field.

📋 Description

• Design and build SecOps tooling covering SIEM, SOAR, vulnerability detection and management, EDR, logging pipelines and user behaviour analytics • Develop architectural patterns and solution designs for the security tool ecosystem • Evaluate and integrate new tools and platforms to strengthen detection, response and automation capabilities • Build and maintain scalable data ingestion, correlation and alerting workflows for advanced detection and response • Coordinate with operational engineers to jointly maintain SecOps workflows and ensure platform reliability • Build automation scripts, playbooks and workflows in SOAR tooling to enhance response efficiency and reduce analyst workload • Design and build an internal SecOps product providing detection and response capabilities for vulnerabilities, threats and security events • Integrate with the internal observability product and broader corporate SOC capabilities • Provide technical management during incidents, including tooling behaviour, data quality and engineering fixes • Develop, test and operationalise detection capabilities based on evolving threats and platform telemetry • Create and maintain detection-as-code artefacts such as Sigma rules, YARA, KQL queries and static analysis rules • Validate detection quality through adversary simulation, purple-teaming or continuous tuning

🎯 Requirements

• 5+ years of experience in security operations, engineering and cloud security tooling • Engineering background in SIEM/SOAR, EDR platforms, log ingestion, telemetry pipelines, scripting (Python, PowerShell, Go) and cloud-native security tooling • Experience with infrastructure-as-code, CI/CD toolchains and container orchestration (Kubernetes) • Experience with threat modelling, detection engineering frameworks, TTP matrices and MITRE ATT&CK • Experience creating architectural diagrams, interface specifications and onboarding guidelines • Experience with logging and detection solutions for cloud architecture • Fluent English, spoken and written • Experience with Wazuh • Familiarity with observability platforms and OpenTelemetry • Background in SOC Analyst Tier 1-3 roles or understanding of security operations centres • Knowledge of security frameworks including BSI, ISO 27001 and MITRE ATT&CK • Experience with GCP or other public cloud providers • DFIR or blue team certifications (CySA+, GIAC, GCIH, BTL) • Kubernetes security experience (CKS or CNCF related)

🏖️ Benefits

• Flexible working hours • Freedom to choose your own projects • Access to exciting projects in various industries • Career advancement support • Competitive pay • Dedicated team support for questions • Opportunity to work independently • Access to a strong professional network

Apply Now