CareerPlanSign in

SIEM/SOC Experte / Detection Engineer (m/w/d)

Bayreuth, BAYERN🌐 Remote💼 Full-time💰 $40,000–$60,000🗓 2026-07-24 → 2026-09-26

Core

Develop and optimize detection use cases for real-world attack scenarios within SIEM and SOC environments to enable early identification and professional handling of security incidents.

Role type

Detection Engineer (SIEM/SOC)

Builds

Detection rules, alerting logics, and security monitoring workflows for Elastic and Microsoft Sentinel

Domain

Cybersecurity, SIEM, SOC, Log Analysis

Deliverable

production ML models | product features | dashboards & analysis

Required skills

SIEM/SOC operations, Elastic, Microsoft Sentinel, Log data analysis, Detection rule development, Incident analysis, Log parsing and normalization, Alerting logic optimization, False positive reduction, SIEM performance optimization, Technical attack reconstruction

Preferred skills

KQL, EQL, Lucene, Sigma, Microsoft Defender XDR, Azure, Sysmon, MITRE ATT&CK, Threat Intelligence, Incident Response, Managed Security Services

Technologies

Elastic, Microsoft Sentinel, Windows, Linux, Firewall, Proxy, EDR/XDR, Cloud, Network logs

Responsibilities

Integrate log sources (Windows, Linux, Firewall, Proxy, EDR/XDR, Cloud, Network, Identities) into SIEM platforms; Develop, test, and optimize detection use cases for realistic attack scenarios; Analyze security incidents and derive appropriate measures; Improve data quality, parsers, normalization, and alerting logics; Reduce false positives and refine existing detection rules; Optimize SIEM performance, data volume, queries, and costs; Document technical adjustments and analysis paths; Collaborate with internal teams and clients to evolve SOC/SIEM processes

Seniority

Mid-level to Senior, hands-on IC

Sourced via bundesagentur · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.