A senior security operations role for a large IT operations provider to banks, insurers and financial institutions, running applications, cloud services and data centres for its clients. At Level 3 you lead the response to the most complex security incidents and develop the SOC around you.
The role
- Leading the operational response to complex and critical incidents at Level 3, including the containment and remediation of advanced persistent threats.
- Digital forensics: memory forensics, timeline reconstruction and artefact analysis on endpoints, servers and cloud environments.
- Proactive threat hunting across the network, using global threat intelligence.
- Detection engineering: developing and testing detection rules and use cases in SIEM, EDR and XDR platforms, based on MITRE ATT&CK.
- Static and dynamic malware analysis.
- Mentoring Level 1 and 2 analysts, and writing playbooks and runbooks.
- Explaining complex technical findings to management, internal stakeholders and customers during and after incidents.
What is needed
- A degree in computer science, information security or a comparable technical qualification.
- At least three to five years in a security operations centre or incident response team.
- Hands-on experience with forensic tools such as EnCase, FTK, Volatility, X-Ways, Autopsy or KAPE.
- Solid knowledge of SIEM, SOAR and EDR/XDR technologies, network protocols, and Windows, Linux, macOS and cloud infrastructure.
- Scripting for automation, preferably Python or PowerShell.
- Business-fluent German (C1 or above) and fluent English.
Certifications in incident response and forensics, such as GCFE, GCFA, GCIH, EnCE or CHFI, are an advantage.