Sign up to save this job, get alerts, and apply with an optimized CV.

Security Engineer (SOC) (m/f/d)

Full Time Remote Executive

Job description

APT-ONE GmbH in Berlin is a consulting firm specializing in Cyber Security. We effectively protect our clients' IT, OT, Cloud, and AI systems from digital threats.

Our approach is different: AI-powered tools handle discovery, routine analysis, and pattern recognition – our consultants validate, interpret, and focus on strategy and tailor-made solutions. This results in deeper analyses and robust decision-making bases in less time, with 40–60% less effort for routine work.

AI only with the highest sensitivity to customer Data protection is paramount over any efficiency gain. AI exclusively on contractually secured, data protection-compliant platforms, minimized and anonymized data, never customer data in model training. We expect this approach – and the willingness to continuously develop our processes and products with AI – from all consultants.

The focus of this role is Detection Engineering: SIEM and XDR platforms, log quality, Detection as Code, and automation – securely in KQL, Sigma, and MITRE ATT&CK.

You are in the right place with us if:

  • you want an attractive fixed salary plus above-average profit sharing.
  • you want to work on highly relevant projects in Security Operations and AI Security independently of location.
  • you see AI as leverage and want to rethink security consulting – without compromising data protection.
  • you want to expand your expertise in SOC platforms, Detection Engineering, and automation.

Responsibilities

  • Setup, operation, and further development of SOC platforms (SIEM, SOAR, EDR/XDR)
  • Onboarding new log sources including parsing, normalization, and ensuring data quality
  • Development and optimization of detection rules and use cases (Sigma, KQL, SPL) based on MITRE ATT&CK
  • Automation of analysis and response processes through playbooks and scripting (Python, PowerShell)
  • Setup of Detection-as-Code pipelines including versioning, testing, and CI/CD
  • Integration and operationalization of Threat Intelligence
  • Close collaboration with analysts and incident responders to reduce false positives and improve detection quality
  • Technical support during security incidents
  • Creation of runbooks, use case documentation, and technical concepts
  • Use of AI-powered tools for log analysis, rule and playbook design, and documentation – including expert validation and approval of results

Qualifications

  • Confident use of AI tools in daily consulting practice, including critical evaluation of results
  • Strong awareness of confidentiality when using AI: You know which data is allowed in which system and are aware of the risks (data exfiltration, model training, prompt injection)
  • Willingness to continuously develop processes and products based on AI
  • At least 5 years of experience in IT/Cyber Security, with several years in architecture or consulting roles
  • Broad technological understanding across network, endpoint, identity, application, and cloud
  • Experience with Zero Trust and segmentation concepts as well as IAM/PAM (Entra ID, Active Directory)
  • Proficient use of ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, SABSA/TOGAF
  • Knowledge in cryptography, PKI, and secure application design
  • Fluent German and English language skills

Of great advantage:

  • Cloud Architect Know-how: Design, securing, and operation of cloud and hybrid environments (Azure, AWS, GCP), cloud-native security services, Infrastructure-as-Code
  • Experience with Prompt Engineering, AI Agents, or LLM integration into workflows
  • Knowledge in AI Governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM)
  • Experience in regulated environments (KRITIS, Financial Sector, Industry/OT)

Certifications (nice to have):

OffSec (Hands-on & Offensive/Defensive Integration)

  • OSDA (Defense Analyst – SOC-200): the direct hit – detection, SIEM analysis, log evaluation, and attack traces in live environments.
  • OSCP (PEN-200): purely offensive, but highly regarded in Detection Engineering – effective Sigma and KQL rules require an understanding of attack mechanics. SANS / GIAC (Architecture & Tactical Detection)
  • GCDA (SANS SEC555): the exactly fitting certification – SIEM optimization, log parsing, normalization, tactical detection rules.
  • GDSA (SANS SEC530): modern security architectures and the foundation for the integration of EDR/XDR, SIEM, and network telemetry.
  • GCIH (SANS SEC504): interface to analysts and incident response – understanding attack techniques, reducing false positives.

Complementary Profile Sharpening

  • SANS SEC586 (Blue Team Automation): perfectly suited for Detection-as-Code, CI/CD pipelines, and SOAR playbooks in Python and PowerShell.
  • Microsoft SC-200: practical handling of Sentinel, Defender XDR, and KQL in daily SOC operations.

Benefits

  • Fixed salary starting from €80,000 plus profit sharing up to €70,000
  • Flexible working hours, remote work, 30 days of vacation
  • IT equipment such as Apple MacBook
  • Regular team events
  • Company pension and health insurance, shopping and employee discounts

Become part of APT-ONE and make security your mission

Find more English Speaking Jobs in Germany on Arbeitnow

Sign up to apply

Create a free account to apply for this job and get access to:

  • AI-powered CV optimization for this specific job
  • Save jobs and create custom alerts
  • See your CV match score for each job

Company information

Company
APT-ONE GmbH
Location
Berlin
Germany
Posted
1 day ago

Find similar jobs

Explore more opportunities like this one.

Interested in this position?

Create your free account and tailor your CV to match this job.