Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Cologne
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you analyze security incidents, conduct forensic investigations, and develop detection rules to proactively identify threats and respond promptly.
Job Technologies
Your role in the team
- Responsibility & Ownership: You take end-to-end ownership of confirmed security incidents, conduct the complete threat analysis until completion, and serve as the primary contact for the customer, including independently coordinating all measures throughout the incident lifecycle.
- Analysis & Visibility: You determine the full extent of the attack (affected systems, attack vectors, activity status) and reconstruct timelines including lateral movement and IOC analysis based on EDR, SIEM, firewall logs, and other data sources.
- Response & Forensics: You initiate containment measures within the scope of contractual authority or after client approval, oversee cleanup and recovery, and conduct in-depth forensic analyses for complex incidents (APT, Ransomware, Zero-Day), including malware, memory, persistence, and attack path analysis.
- Documentation & Detection: You document incidents in a structured manner (final reports, forensic reports), conduct proactive threat hunting based on current threat intelligence regardless of incoming alerts, and derive new detection requirements including specific rule proposals.
- Enablement & Reporting: You enhance the quality of the L1 team through runbooks, shadowing, and training, and support regular customer reports with well-founded situation assessments and concrete action recommendations.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Understanding of Attacks & Frameworks: Solid understanding of modern attack techniques, lateral movement, and complex attack chains based on MITRE ATT&CK.
- Detection & Engineering: Practical experience in the development, optimization, and continuous improvement of detection rules.
- Communication & Working Style: Strong communication skills in customer contact, a structured and documentation-driven working approach, as well as business-fluent German and fluent English in spoken and written form.
Experience
- Experience & Expertise: Several years of experience in operational security analysis, ideally within SOC or MSSP environments, combined with solid knowledge of SIEM platforms and EDR solutions.
- Forensics & Threat Hunting: Experience in digital forensics (Memory, Malware analysis, Artifact evaluation) as well as in Threat Hunting and working with Threat Intelligence platforms and feeds.
This text has been machine translated. Show original
What we offer
- Humanity & Flexibility: With us, you are not just an anonymous employee number. We foster an open 'Du' culture in our family-owned company and offer you the perfect balance through remote work from home or at our Cologne headquarters.
- Technology of tomorrow: Dive into high-end security and network solutions. Together with your team, you will manage top infrastructures for our clients.
- Knowledge advantage & freedom of movement: Stay at the forefront of technology. We offer you tailored training programs at the cutting edge, as well as short decision-making processes, flat hierarchies, and maximum agility for your ideas.
- Strong Team & Sense of Purpose: Look forward to a work environment characterized by trust, support, and genuine team spirit. At Telonic, you take responsibility and actively shape the digital world of tomorrow.
This text has been machine translated. Show original
Topics You Will Work On
Job Locations
About Your Employer
Telonic GmbH
Telonic GmbH ist eines der führenden Systemhäuser in Deutschland für Leistungen rund um die IT-Infrastruktur.
Description
- Company Size
- 50-249 Employees
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Trade