Description
Summary:
Join as a Security Operations Engineer to embed security and compliance across a cloud-native platform, focusing on SecOps tooling, detection engineering, and incident response.
Highlights:
1. Shape 24x7 security operations capability for a cloud-native platform
2. Develop and operationalize new detection capabilities against evolving threats
3. Build systems and automation for scalable security operations
**About the Role**
We're looking for a Security Operations Engineer to join Information Security Risk and Compliance (ISRC), the team responsible for embedding security and compliance across a cloud\-native platform that powers software product development for the energy sector.
The platform is a hybrid\-cloud, service\-oriented environment giving application teams self\-service capabilities across infrastructure, data, delivery, and operations. ISRC ensures this platform — and everything built on it — stays secure, resilient, and trustworthy.
You'll work at the intersection of SecOps tooling, detection engineering, and incident response, building the systems and automation that keep the platform's security operations sharp and scalable.
**What You'll Do**
**SecOps Tooling Engineering**
* Design and build SecOps tooling as part of the broader security tool ecosystem
* Develop architecture patterns and solution designs for SIEM, SOAR, vulnerability detection \& management, EDR, logging pipelines, and user behavior analytics
* Evaluate and integrate new tools and platforms to strengthen detection, response, and automation
* Build and maintain scalable data ingestion, correlation, and alerting workflows
* Automate repetitive security operations tasks — playbooks, scripts, and workflows (e.g., in SOAR tools)
* Help shape a structured 24x7 security operations capability
**Incident Response**
* Provide technical support during incidents, focusing on tooling, data quality, and engineering fixes
* Improve detection content, correlation rules, dashboards, and data models based on real incident patterns
* Support rapid instrumentation, log onboarding, and custom tooling during active security events
**Detection Engineering**
* Develop, test, and operationalize new detection capabilities based on evolving threats and platform telemetry
* Create and maintain detection\-as\-code artifacts (Sigma, YARA, KQL, static analysis rules)
* Validate detection quality through adversary simulation and purple\-teaming
* Keep rules documented, version\-controlled, and validated against production data
**What We're Looking For**
**Must\-have:**
* 5\+ years of experience in security operations, engineering, and cloud security tooling
* Hands\-on experience with SIEM/SOAR, EDR platforms, log ingestion, and telemetry pipelines
* Scripting proficiency (Python, PowerShell, or Go)
* Experience with infrastructure\-as\-code, CI/CD toolchains, and Kubernetes
* Familiarity with threat modeling, detection engineering frameworks, TTP matrices, and MITRE ATT\&CK
* Experience creating architectural diagrams, interface specs, and onboarding guides
* Experience with logging and detection for cloud architectures
* Fluent English (C1 or above)
**Nice\-to\-have:**
* Experience with Wazuh
* Familiarity with observability platforms / OpenTelemetry
* Background as a SOC Analyst (Tier 1–3\) or solid understanding of SOC operations
* Knowledge of security frameworks (BSI, ISO 27001, MITRE ATT\&CK, etc.)
* Experience with GCP or another public cloud provider
* DFIR / blue team certifications (CySA\+, GIAC, GCIH, BTL)
* Kubernetes security certification (CKS or CNCF\-related)
**Location:** Remote from EU (Travels to Germany foreseen)
**Type:** Full\-time
**Sector:** Energy