Security Operations Engineer (SIEM/SOAR)
Core
Designing and maintaining detection logic and automated response workflows for the Cyber Defense Center to neutralize cyber threats.
Role type
Security Operations Engineer (SIEM/SOAR)
Builds
Detection use cases, analytic rules, SOAR playbooks, and custom queries for the Cyber Defense Center.
Domain
Cybersecurity, SIEM, SOAR, Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM rule tuning, SOAR playbook design, MITRE ATT&CK alignment, log parsing and normalization, SIEM query languages (KQL, SPL, AQL), Sigma framework, API integrations, technical documentation
Preferred skills
Python scripting, PowerShell automation, German language proficiency
Technologies
SIEM, EDR, SOAR, KQL, SPL, AQL, Sigma
Responsibilities
Define detection use cases aligned with threat intelligence; maintain and modify SIEM/EDR analytic rules; design and configure SOAR response playbooks; manage watchlists and exception lists; create custom queries and reports for investigations; assist SOC analysts with integration troubleshooting.
Seniority
Mid-level, hands-on IC