Sign up to save this job, get alerts, and apply with an optimized CV.
Security Engineer (SOC) (m/f/d)
Job description
APT-ONE GmbH in Berlin is a consulting firm specializing in Cyber Security. We effectively protect our clients' IT, OT, Cloud, and AI systems from digital threats.
Our approach is different: AI-powered tools handle discovery, routine analysis, and pattern recognition – our consultants validate, interpret, and focus on strategy and tailor-made solutions. This results in deeper analyses and robust decision-making bases in less time, with 40–60% less effort for routine work.
AI only with the highest sensitivity to customer Data protection is paramount over any efficiency gain. AI exclusively on contractually secured, data protection-compliant platforms, minimized and anonymized data, never customer data in model training. We expect this approach – and the willingness to continuously develop our processes and products with AI – from all consultants.
The focus of this role is Detection Engineering: SIEM and XDR platforms, log quality, Detection as Code, and automation – securely in KQL, Sigma, and MITRE ATT&CK.
You are in the right place with us if:
- you want an attractive fixed salary plus above-average profit sharing.
- you want to work on highly relevant projects in Security Operations and AI Security independently of location.
- you see AI as leverage and want to rethink security consulting – without compromising data protection.
- you want to expand your expertise in SOC platforms, Detection Engineering, and automation.
Responsibilities
- Setup, operation, and further development of SOC platforms (SIEM, SOAR, EDR/XDR)
- Onboarding new log sources including parsing, normalization, and ensuring data quality
- Development and optimization of detection rules and use cases (Sigma, KQL, SPL) based on MITRE ATT&CK
- Automation of analysis and response processes through playbooks and scripting (Python, PowerShell)
- Setup of Detection-as-Code pipelines including versioning, testing, and CI/CD
- Integration and operationalization of Threat Intelligence
- Close collaboration with analysts and incident responders to reduce false positives and improve detection quality
- Technical support during security incidents
- Creation of runbooks, use case documentation, and technical concepts
- Use of AI-powered tools for log analysis, rule and playbook design, and documentation – including expert validation and approval of results
Qualifications
- Confident use of AI tools in daily consulting practice, including critical evaluation of results
- Strong awareness of confidentiality when using AI: You know which data is allowed in which system and are aware of the risks (data exfiltration, model training, prompt injection)
- Willingness to continuously develop processes and products based on AI
- At least 5 years of experience in IT/Cyber Security, with several years in architecture or consulting roles
- Broad technological understanding across network, endpoint, identity, application, and cloud
- Experience with Zero Trust and segmentation concepts as well as IAM/PAM (Entra ID, Active Directory)
- Proficient use of ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, SABSA/TOGAF
- Knowledge in cryptography, PKI, and secure application design
- Fluent German and English language skills
Of great advantage:
- Cloud Architect Know-how: Design, securing, and operation of cloud and hybrid environments (Azure, AWS, GCP), cloud-native security services, Infrastructure-as-Code
- Experience with Prompt Engineering, AI Agents, or LLM integration into workflows
- Knowledge in AI Governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM)
- Experience in regulated environments (KRITIS, Financial Sector, Industry/OT)
Certifications (nice to have):
OffSec (Hands-on & Offensive/Defensive Integration)
- OSDA (Defense Analyst – SOC-200): the direct hit – detection, SIEM analysis, log evaluation, and attack traces in live environments.
- OSCP (PEN-200): purely offensive, but highly regarded in Detection Engineering – effective Sigma and KQL rules require an understanding of attack mechanics. SANS / GIAC (Architecture & Tactical Detection)
- GCDA (SANS SEC555): the exactly fitting certification – SIEM optimization, log parsing, normalization, tactical detection rules.
- GDSA (SANS SEC530): modern security architectures and the foundation for the integration of EDR/XDR, SIEM, and network telemetry.
- GCIH (SANS SEC504): interface to analysts and incident response – understanding attack techniques, reducing false positives.
Complementary Profile Sharpening
- SANS SEC586 (Blue Team Automation): perfectly suited for Detection-as-Code, CI/CD pipelines, and SOAR playbooks in Python and PowerShell.
- Microsoft SC-200: practical handling of Sentinel, Defender XDR, and KQL in daily SOC operations.
Benefits
- Fixed salary starting from €80,000 plus profit sharing up to €70,000
- Flexible working hours, remote work, 30 days of vacation
- IT equipment such as Apple MacBook
- Regular team events
- Company pension and health insurance, shopping and employee discounts
Become part of APT-ONE and make security your mission
Find more English Speaking Jobs in Germany on Arbeitnow
Required skills
Sign up to apply
Create a free account to apply for this job and get access to:
- AI-powered CV optimization for this specific job
- Save jobs and create custom alerts
- See your CV match score for each job
Company information
- Company
- APT-ONE GmbH
- Location
-
Berlin
Germany - Posted
- 1 day ago
Interested in this position?
Create your free account and tailor your CV to match this job.