Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Cologne
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will handle security incidents, conduct threat analyses, and coordinate actions throughout the incident lifecycle while communicating closely with clients.
Job Technologies
Your role in the team
- You take over confirmed security incidents end-to-end, conduct the complete threat analysis until completion, and serve as the primary contact for the customer, including independent coordination of all measures throughout the incident lifecycle.
- You determine the entire scope of the attack (affected systems, attack vectors, activity status) and reconstruct timelines including lateral movement and IOC analysis based on EDR, SIEM, firewall logs, and other data sources.
- You initiate containment measures within the scope of contractual authority or upon customer approval, oversee cleanup and recovery, and conduct in-depth forensic analyses for complex incidents (APT, Ransomware, Zero-Day), including malware, memory, persistence, and attack path analysis.
- You document incidents in a structured manner (closure reports, forensic reports), conduct proactive threat hunting based on current threat intelligence regardless of incoming alerts, and derive new detection requirements including specific rule proposals.
- You enhance the quality of the L1 team through runbooks, shadowing, and training, and support regular customer reports with well-founded situation assessments and concrete recommendations for action.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Secure understanding of modern attack techniques, lateral movement, and complex attack chains based on MITRE ATT&CK.
- Practical experience in the development, optimization, and continuous improvement of detection rules.
- Strong communication skills in customer contact, a structured and documentation-driven work approach, as well as proficiency in German (negotiation level) and fluency in English, both spoken and written.
Experience
- Several years of experience in operational security analysis, ideally within a SOC or MSSP environment, combined with solid knowledge of SIEM platforms and EDR solutions.
This text has been machine translated. Show original
What we offer
- With us, you are not just an anonymous personnel number.
- We foster an open 'Du' culture in our family-owned company and offer you the perfect balance through flexible remote work from home or at our Cologne headquarters.
- Immerse yourself in high-end security and network solutions.
- Together with your team, you manage top infrastructures at our clients.
- Stay at the forefront of technology.
- We offer you tailored training programs at the cutting edge, as well as short decision-making processes, flat hierarchies, and maximum agility for your ideas.
- Look forward to a work environment characterized by trust, support, and genuine team spirit.
- At Telonic, you take responsibility and actively shape the digital world of tomorrow.
This text has been machine translated. Show original
Topics that you deal with on the job
Job Locations
This is your employer
Telonic GmbH
Telonic GmbH ist eines der führenden Systemhäuser in Deutschland für Leistungen rund um die IT-Infrastruktur.
Description
- Company Size
- 50-249 Employees
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Trade