openqareer

Security Operations Engineer (PID0632/0633)

Interval · Удалённо · United States

# Security Operations Engineer (PID0632/0633) **Interval** · United States · `Remote` · `Contractor` 💼 **Уровень роли:** `Mid-level` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Himalayas (JSON API)* --- ### Top Skills & Match 🎯 **Ключевой стек роли:** `[Security-Operations-Engineer]` `[Detection-Engineering]` `[SecOps-Engineer]` `[Security-Engineer]` `[SOC-Analyst]` `[Cybersecurity-Operations-Engineer]` `[Cyber-Operations-Engineer]` `[Operational-Technology-Security-Engineer]` `[Security-Infrastructure-Engineer]` --- ### About the Role This is a remote position. We are seeking a Security Operations Engineer to join the Information Security, Risk and Compliance function of a large internal platform programme in the energy sector. Working within a cloud-native, hybrid platform environment, you will design and build the SecOps tooling ecosystem, develop detection capabilities and support incident response activities as the programme scales towards a structured 24x7 security operations capability. Contract / Freelance Full-time hours Remote, onsite in Germany possible What you'll be doing Designingand building SecOps tooling coveringSIEM, SOAR, vulnerability detection andmanagement, EDR, logging pipelines anduser behaviour analytics Developingarchitectural patterns and solutiondesigns for the security toolecosystem Evaluating and integratingnew tools and platforms to strengthendetection, response and automationcapabilities Building and maintainingscalable data ingestion, correlationand alerting workflows foradvanced detection and response Coordinating with operational engineersto jointly maintain SecOpsworkflows and ensure platformreliability Building automationscripts, playbooks and workflows inSOAR tooling to enhanceresponse efficiency and reduce analystworkload Designing and building aninternal SecOps product providingdetection and response capabilitiesfor vulnerabilities, threats andsecurity events Integrating with theinternal observability product andbroader corporate SOC capabilities Providing technicalmanagement during incidents, includingtooling behaviour, data quality andengineering fixes Developing, testingand operationalising detectioncapabilities based on evolving threatsand platform telemetry Creating andmaintaining detection-as-codeartefacts such as Sigma rules, YARA,KQL queries andstatic analysis rules Validatingdetection quality throughadversary simulation, purple-teamingor continuous tuning Requirements What you'll need 5+ years of experience in security operations, engineering and cloud security tooling Engineering background in SIEM/SOAR, EDR platforms, log ingestion, telemetry pipelines, scripting (Python, PowerShell, Go) and cloud-native security tooling Experience with infrastructure-as-code, CI/CD toolchains and container orchestration (Kubernetes) Experience with threat modelling, detection engineering frameworks, TTP matrices and MITRE ATT&CK Experience creating architectural diagrams, interface specifications and onboarding guidelines Experience with logging and detection solutions for cloud architecture Fluent English, spoken and written Desirable Experience with Wazuh Familiarity with observability platforms and OpenTelemetry Background in SOC Analyst Tier 1-3 roles or understanding of security operations centres Knowledge of security frameworks including BSI, ISO 27001 and MITRE ATT&CK Experience with GCP or other public cloud providers DFIR or blue team certifications (CySA+, GIAC, GCIH, BTL) Kubernetes security experience (CKS or CNCF related) Benefits As a freelancer / contractor with us, you will enjoy flexible working hours and the freedom to choose your own projects. Our platform gives you access to exciting projects in various industries and supports you in advancing your career. You'll benefit from competitive pay and a dedicated team to help you with any questions you may have. Work independently and utilise our strong network to achieve your professional goals. Originally posted on Himalayas

Наблюдалась 2026-09-21, впервые 2026-09-21, источник — Himalayas (JSON API).

Открыть у работодателя