Job
- Level
- Senior
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Hamburg, Ismaning, Leinfelden, Görlitz, Berlin, Karlsruhe, Nuremberg, Dusseldorf, Cologne, Passau, Frankfurt, Brunswick, Dresden, Münster (Hessen), Essen, Chemnitz, Heidelberg, Hanover
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will analyze security alerts and handle incidents within modern SIEM and EDR environments, conduct proactive threat hunting, and develop tailored detection use cases.
Job Technologies
Your role in the team
- Analysis, prioritization, and handling of security alerts and incidents in modern SIEM, EDR, and XDR platforms.
- Proactive threat hunting to identify previously unknown threats based on current attack patterns and own hypotheses.
- In-depth analysis of log data, network traffic, endpoints, and cloud environments to detect security-related anomalies and attacks.
- Independent execution of incident response measures as well as coordination and follow-up of security-related incidents.
- Assessment of current cyber threats, vulnerabilities, and attack campaigns in terms of their relevance to client and corporate environments.
- Development, optimization, and quality assurance of detection use cases, correlation rules, and alerting strategies.
- Support in root cause analysis as well as forensic investigations to clarify complex security incidents.
- Conducting vulnerability analyses and supporting technical security assessments.
- Documentation and presentation of analysis results as well as derivation of appropriate action recommendations for internal and external stakeholders.
- Active participation in shaping and continuous development of processes, playbooks, automations, and best practices in the SOC environment.
- Participation in a high-performance Security Operations Center to ensure professional 24/7 security monitoring and incident management.
This text has been machine translated. Show original
Our expectations of you
Education
- Successfully completed studies in Computer Science, Cyber Security, or a comparable qualification through education and relevant practical experience.
Qualifications
- In-depth knowledge of operating systems (Windows and Linux), networks, Active Directory, as well as modern IT and cloud infrastructures.
- Good knowledge in the analysis and assessment of cyberattacks, attack techniques, and threat actors, as well as common frameworks such as MITRE ATT&CK.
- Proficient in log analysis, security events, and complex technical contexts.
- Knowledge of KQL, Detection Engineering, or Security Automation is advantageous.
- Certifications such as Microsoft SC-200, AZ-500, Security+, CySA+, GCIH, or comparable qualifications are desirable.
- Strong analytical skills, a structured way of working, and the ability to remain composed even in critical situations.
- Strong team orientation, initiative, and willingness to take responsibility and actively share knowledge.
- Excellent German and English language skills, both written and spoken.
- Willingness to work in shifts at a modern Security Operations Center.
Experience
- Several years of practical experience in Security Operations, Security Monitoring, Incident Response, or Threat Detection.
- Experience with SIEM, EDR, or XDR solutions, ideally Microsoft Sentinel / Defender XDR, Palo Alto Cortex XSIAM / XDR, or comparable platforms.
- Experience in Threat Hunting as well as a good understanding of current threat landscapes and attack methods.
This text has been machine translated. Show original
What we offer
- Living Culture "People-Centered"
- Sustainable Projects & Social Engagement
- Promotion of Diversity & Equal Opportunities
- Trustworthy team spirit & creative freedom
- Tailored Development & Mentoring
- Flexible working & work-life integration
- Corporate Benefits
- Mobile Working
This text has been machine translated. Show original
Benefits
Health, Fitness & Fun
Work-Life-Integration
Food & Drink
Topics You Will Work On
Job Locations
About Your Employer
Msg Group
The msg Group is an international company with over 8,000 employees that offers its customers a comprehensive range of services. This includes not only innovative strategic consulting, but also intelligent IT solutions that create sustainable value. The msg group is active in the following industries: Automotive industry, financial services, food industry, insurance industry and telecommunications as well as the energy industry.
Description
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication