← Back to list
Job

SIEM/SOC Expert / Detection Engineer

Other • Hybrid • Full-time • Germany Bayreuth, Germany

SIEM/SOC expert at eyeDsec: connecting log sources to Elastic and Microsoft Sentinel, developing detection use cases and analyzing security incidents. Remote or hybrid work, annual gross salary of EUR 40,000-60,000 for junior and EUR 60,000-90,000 for senior level.

Stack

Responsibilities

  • ▹Connect log sources from Windows, Linux, firewall, proxy, EDR/XDR, cloud, network and identities to Elastic and/or Microsoft Sentinel
  • ▹Develop, test and continuously optimize detection use cases for real attack scenarios
  • ▹Analyze security incidents, assess anomalies and derive suitable measures
  • ▹Review and improve data quality, parsers, normalization, field mapping and alerting logic
  • ▹Reduce false positives and sharpen existing detection rules in a practical way
  • ▹Optimize SIEM performance, data volume, queries and cost aspects
  • ▹Document use cases, analysis paths and technical changes in a traceable way
  • ▹Work with internal teams and customers and further develop SOC/SIEM processes

Requirements

  • ▹Professional experience in SIEM, SOC, security monitoring, detection engineering or incident analysis
  • ▹Hands-on experience with Elastic and/or Microsoft Sentinel and production SIEM environments
  • ▹Solid understanding of log sources, detection rules, use cases and incident analysis
  • ▹Ability to trace attacks technically and spot traces in log data
  • ▹Good understanding of IT infrastructures, networks, Windows/Linux and cloud services

Nice to have

  • ▹KQL, EQL, Lucene, Sigma or comparable query/detection languages
  • ▹Microsoft Defender XDR, Azure, Sysmon, firewall, proxy, EDR/XDR or network logs
  • ▹MITRE ATT&CK, incident response, threat intelligence or vulnerability management
  • ▹Experience in customer projects, managed security services or SOC environments

Soft skills

Analytical thinkingStructured way of working and a high degree of independenceClear communication with technical teams, customers and internal contacts

What we offer

  • ▹Remote or hybrid work, 30 days of vacation and attractive pay
  • ▹Short decision paths, autonomy and exciting security projects
  • ▹Development in SIEM, SOC and detection engineering
  • ▹Extras such as Edenred, JobRad, internet allowance and daycare subsidy

About the company

eyeDsec Information Security works on modern SIEM and SOC topics and helps companies detect security incidents early, classify them correctly and handle them professionally.

Similar jobs