Job
- Level
- Lead
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Munich
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will create high-fidelity detection rules, analyze cyber threats, and develop automated response playbooks to enhance security posture and support the SOC.
Job Technologies
Your role in the team
- Lead Detection Strategy: Define the long-term vision for detection engineering, aligning technical roadmaps with organizational risk profiles while standardizing the development lifecycle.
- Engine & Rule Lifecycle Management: Architect, develop, maintain, and optimize high-fidelity detection rules for the SOC while expanding framework coverage against MITRE ATT&CK® and Sigma standards.
- Threat Intelligence Translation: Analyze Cyber Threat Intelligence (CTI) and translate complex TTPs into proactive, resilient detection logic.
- Automation & Orchestration: Drive 'Detection-as-Code' initiatives and engineer automated response playbooks to streamline incident response and minimize manual intervention.
- Technical Mentorship & Escalation: Act as the primary escalation point for complex technical issues, mentoring junior detection engineers and SOC analysts.
- Cross-Functional Collaboration: Partner closely with Incident Response and SOC teams to ensure deployment of context-rich detections that enable rapid threat containment.
This text has been machine translated. Show original
Our expectations of you
Education
- Degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
Qualifications
- Deep technical expertise in Windows and Linux operating systems, including OS internals, system logging, and telemetry analysis.
- Practical background in Red Teaming, Penetration Testing, or an offensive mindset to anticipate attacker methodologies.
- Advanced expertise with the MITRE ATT&CK® framework and Detection-as-Code concepts.
- Strong communication skills with an empathetic, collaborative approach to leading cross-functional teams and technical initiatives.
Experience
- Proven track record in developing use cases and detection logic within a Security Operations Center (SOC) environment, including leadership or mentorship experience.
- Strong proficiency in Python and hands-on experience with automation frameworks to streamline operations.
This text has been machine translated. Show original
What we offer
- Fair Compensation & Extras: Attractive remuneration and individual additional benefits, such as company pension schemes, mobility offers (e.g., bike leasing), or corporate discounts with partner companies in accordance with our current guidelines.
- Time for You (and Your Loved Ones): 30 days of annual leave based on our collective agreement (35-hour week); work-life balance through flexible working hours (flextime), mobile working, part-time options, job sharing, and sabbatical opportunities.
- Growth Made Easy: Excellent professional development opportunities and international, group-wide career perspectives.
- Feel Good at Work: On-site company doctor; comprehensive health programs (sports courses, preventive care, etc.), canteen and cafeteria, and local childcare facilities at selected locations.
- Diversity Connects: Work in a diverse environment with more than 140 nationalities, where exchange, mutual support, and inclusion are part of our DNA.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Food & Drink
Higher Take-Home Pay
Topics You Will Work On
Job Locations
About Your Employer
Airbus Deutschland GmbH
Airbus is the world's leading provider of air and space transportation, as well as related services.
Description
- Language
- English
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Vehicle Manufacturing, Supplier, Industry, Production
Employer reviews
by devworkplaces.com
Total
(1 Review)3.3
Career Growth
3.2Engineering
2.8Workingconditions
4.0Culture
3.5