Security Engineer (SOC) (m,f,x)
Core
Improve HelloFresh's Security Logging & Monitoring Program by maturing tools, processes, and playbooks to reduce dwell time (MTTD & MTTR) through SOC monitoring, triage, and advisory.
Role type
Security Engineer (SOC)
Builds
Cloud-native SIEM platforms, automated security solutions (EDR/EPP, Firewalls, IDS/IPS), and incident response workflows.
Domain
Cybersecurity, Cloud Security (AWS), SOC Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Security monitoring, incident response, cloud SIEM & SOAR platforms, DDoS mitigation, Layer-7 web security, network intrusion methods, EDR/EPP/MDM operations, log analysis (ElasticSearch, Splunk/SumoLogic), automation scripting
Preferred skills
Threat intelligence analysis, APT campaign defense, IaC for security, on-call shift management
Technologies
AWS, ElasticSearch, Splunk, SumoLogic, EDR, EPP, MDM, Firewalls, IDS/IPS, SOAR
Responsibilities
Conduct initial triage of security events and document progress throughout the Incident Response Lifecycle; Automate and operate modern security solutions like EDR/EPPs, Firewalls, IDS/IPS, Email Security, VPN, and MDM tools; Leverage threat intel feeds to sweep environments against APT campaigns; Prepare status reports and follow up with stakeholders to close the remediation loop; Facilitate efficient Incident Detection and Response in AWS cloud and enterprise IT environments
Seniority
Mid-level, hands-on IC