Darum lohnt es sich
Responsibilities
• Coordinate Security Operations Center (SOC) operations, ensuring continuous monitoring, rapid response and alignment with the company’s security policies.
• Assess and optimize incident response processes, implementing automation, playbooks and metrics to increase efficiency and reduce response times.
• Perform detailed incident analyses, identifying root causes, impacts and recommending corrective and preventive measures.
• Manage SIEM, SOAR and other monitoring tools, ensuring integration and effectiveness in threat detection.
• Collaborate with cyber defense, GRC, IAM and infrastructure teams to coordinate actions during incidents and improve overall security posture.
• Prepare technical and executive reports on incidents, trends and improvements implemented.
• Train SOC analysts and other stakeholders on incident response best practices and tool usage.
• Stay up to date on new attack techniques, response frameworks (e.g., NIST, MITRE ATT&CK) and industry trends.
Requirements
• Bachelor’s degree in Computer Science, Computer Engineering, Information Systems or related fields.
• Proven experience in incident response, SOC management and investigation of complex incidents.
• Knowledge of EDR/XDR solutions (Microsoft Defender and CrowdStrike).
• Experience with SOAR and process automation.
• Knowledge of network protocols.
• Familiarity with MITRE ATT&CK and NIST frameworks.
• Scripting language skills (Python, PowerShell) for automation.
• Experience with public cloud security (AWS, Azure and/or GCP), including native detection and protection tools, log management in cloud environments and understanding of the shared responsibility model.
• Ability to correlate events, identify patterns and propose effective strategies.
• Strong communication skills to present clear, detailed reports to both technical and executive audiences.
• Commitment to continuous learning and participation in trainings and conferences.
• Ability to collaborate across teams to ensure coordinated responses.
• Nice to have (differentials):
• Certifications such as CEH, CompTIA, SC-200 and cloud security certifications.
• Experience with SIEM (Azure Sentinel).