SIEM/SOC Experte / Detection Engineer (m/w/d)
Core
Develop and optimize detection use cases for real-world attack scenarios within SIEM and SOC environments to enable early identification and professional handling of security incidents.
Role type
Detection Engineer (SIEM/SOC)
Builds
Detection rules, alerting logics, and security monitoring workflows for Elastic and Microsoft Sentinel
Domain
Cybersecurity, SIEM, SOC, Log Analysis
Deliverable
production ML models | product features | dashboards & analysis
Required skills
SIEM/SOC operations, Elastic, Microsoft Sentinel, Log data analysis, Detection rule development, Incident analysis, Log parsing and normalization, Alerting logic optimization, False positive reduction, SIEM performance optimization, Technical attack reconstruction
Preferred skills
KQL, EQL, Lucene, Sigma, Microsoft Defender XDR, Azure, Sysmon, MITRE ATT&CK, Threat Intelligence, Incident Response, Managed Security Services
Technologies
Elastic, Microsoft Sentinel, Windows, Linux, Firewall, Proxy, EDR/XDR, Cloud, Network logs
Responsibilities
Integrate log sources (Windows, Linux, Firewall, Proxy, EDR/XDR, Cloud, Network, Identities) into SIEM platforms; Develop, test, and optimize detection use cases for realistic attack scenarios; Analyze security incidents and derive appropriate measures; Improve data quality, parsers, normalization, and alerting logics; Reduce false positives and refine existing detection rules; Optimize SIEM performance, data volume, queries, and costs; Document technical adjustments and analysis paths; Collaborate with internal teams and clients to evolve SOC/SIEM processes
Seniority
Mid-level to Senior, hands-on IC