Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
You will design and build SecOps tooling, including SIEM and SOAR integrations, to ensure the security and scalability of a cloud-native platform. Additionally, you will lead incident response efforts and develop detection-as-code artifacts to proactively mitigate evolving threats.
About the Role
We're looking for a Security Operations Engineer to join Information Security Risk and Compliance (ISRC), the team responsible for embedding security and compliance across a cloud-native platform that powers software product development for the energy sector.
The platform is a hybrid-cloud, service-oriented environment giving application teams self-service capabilities across infrastructure, data, delivery, and operations. ISRC ensures this platform — and everything built on it — stays secure, resilient, and trustworthy.
You'll work at the intersection of SecOps tooling, detection engineering, and incident response, building the systems and automation that keep the platform's security operations sharp and scalable.
What You'll Do
SecOps Tooling Engineering
Design and build SecOps tooling as part of the broader security tool ecosystem
Develop architecture patterns and solution designs for SIEM, SOAR, vulnerability detection & management, EDR, logging pipelines, and user behavior analytics
Evaluate and integrate new tools and platforms to strengthen detection, response, and automation
Build and maintain scalable data ingestion, correlation, and alerting workflows
Automate repetitive security operations tasks — playbooks, scripts, and workflows (e.g., in SOAR tools)
Help shape a structured 24x7 security operations capability
Incident Response
Provide technical support during incidents, focusing on tooling, data quality, and engineering fixes
Improve detection content, correlation rules, dashboards, and data models based on real incident patterns
Support rapid instrumentation, log onboarding, and custom tooling during active security events
Detection Engineering
Develop, test, and operationalize new detection capabilities based on evolving threats and platform telemetry
Create and maintain detection-as-code artifacts (Sigma, YARA, KQL, static analysis rules)
Validate detection quality through adversary simulation and purple-teaming
Keep rules documented, version-controlled, and validated against production data
What We're Looking For
Must-have:
5+ years of experience in security operations, engineering, and cloud security tooling
Hands-on experience with SIEM/SOAR, EDR platforms, log ingestion, and telemetry pipelines
Scripting proficiency (Python, PowerShell, or Go)
Experience with infrastructure-as-code, CI/CD toolchains, and Kubernetes
Familiarity with threat modeling, detection engineering frameworks, TTP matrices, and MITRE ATT&CK
Experience creating architectural diagrams, interface specs, and onboarding guides
Experience with logging and detection for cloud architectures
Fluent English (C1 or above)
Nice-to-have:
Experience with Wazuh
Familiarity with observability platforms / OpenTelemetry
Background as a SOC Analyst (Tier 1–3) or solid understanding of SOC operations
Knowledge of security frameworks (BSI, ISO 27001, MITRE ATT&CK, etc.)
Experience with GCP or another public cloud provider
DFIR / blue team certifications (CySA+, GIAC, GCIH, BTL)
Kubernetes security certification (CKS or CNCF-related)
Location: Remote from EU (Travels to Germany foreseen)
Type: Full-time
Sector: Energy
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”