SOC Engineer

Nviso

Brussel Hoofdstad

Sur place

EUR 60 000 - 95 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Training budget
Mentor program
Flexible work model
Personal coach
Home office options
Monthly allowances
Extra leave days

Résumé du poste

NVISO is seeking a Senior SOC Engineering Consultant to join its MSS team, based in Greece. You will build, operate and scale the MSS backbone across Microsoft Sentinel, Elastic Cloud, Defender XDR and more, onboarding log sources, configuring forwarders, and shaping scalable engineering patterns.

You will mentor junior colleagues, translate operational needs into actionable roadmaps, and collaborate with customers to ensure proper execution while maintaining NVISO’s values.

Qualifications

  • Hands-on with a major SIEM platform (onboarding/log source parsing/normalization).
  • Solid understanding of SOC operations and incident response workflows.
  • Knowledge of log forwarding tech and centralized collectors.
  • Strong Python or scripting skills with API familiarity.
  • Experience with at least one EDR/XDR ecosystem (Defender/XDR, Cortex XDR, SentinelOne).
  • Familiarity with Azure/AWS from a security telemetry perspective.

Responsabilités

  • Onboard new customer log sources into NVISO’s SIEM platforms with native connectors or NVISO-managed forwarders.
  • Design, deploy and maintain log forwarding infrastructure and forwarder clusters.
  • Develop parsers, normalization and enrichment logic for SIEM data.
  • Configure and integrate EDR/XDR platforms and cloud monitoring into the MSS stack.
  • Support detections engineering with platform-side deployments and testing.
  • Build automations on SOAR (XSOAR) and contribute to Core platform components.
  • Contribute to Self-Service Onboarding and define reusable engineering patterns.
  • Translate customer requirements into implementation roadmaps and timelines.
  • Mentor junior colleagues and act as a technical reference for MSS engineering.

Connaissances

SIEM platforms
SOC operations
Log forwarding
Python scripting
EDR/XDR ecosystems
Cloud telemetry
Engineering patterns
SOAR (XSOAR)
IaC (Bicep/Terraform)

Outils

Logstash
Elastic Agent
Syslog collectors
Terraform
Bicep
Azure Functions

Description du poste

It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private and governmental organizations to help them better prepare for, prevent, detect and respond to cyber security incidents.

All of this is built on four fundamental values that define who we are: We are Proud, We Break Barriers, We Care and No BS!

What will you do?

What will you do?

As a Senior SOC Engineering Consultant, based in Greece, you will help build, operate and scale the technical backbone of NVISO’s Managed Security Services (MSS). You engineer the platforms, integrations and detection infrastructure that our 24×7 Managed Detection & Response service is delivered on, across Microsoft Sentinel, Elastic Cloud, Microsoft Defender XDR, Cortex XDR, SentinelOne, cloud platforms and ISC/OT sensors.

You understand that a modern SOC is only as strong as the telemetry it sees and the platforms it runs on. Your work makes sure that customer log sources are cleanly onboarded, that log forwarding infrastructure is fit for purpose, that detection content is deployed and tested, and that our analysts get high-signal alerts with the context they need to act. As a senior member of the team, you go beyond individual integrations – you shape reusable engineering patterns, mentor more junior colleagues and act as a technical point of reference in engagements with customers.

You support customers and colleagues by translating operational SOC needs into sustainable engineering strategies and practical implementations, covering log onboarding, parsing and normalization, forwarder deployments, SIEM/EDR platform configuration, automation and lifecycle management. You have strong communication and interpersonal skills, which enable you not only to understand requirements, but also to put these requirements into an implementation roadmap, explain it to customers and guarantee proper execution. You have an open and approachable mind, in line with NVISO’s values.

Typical tasks include but are not limited to:

  • Onboarding new customer log sources into NVISO’s SIEM platforms (Microsoft Sentinel, Elastic Cloud), preferring native connectors and falling back to customer-hosted, NVISO-managed log forwarders where required;
  • Designing, deploying and maintaining log forwarding infrastructure – including load-balanced forwarder clusters – that sits in the customer environment and is operated by NVISO;
  • Building and maintaining parsers, normalization and enrichment logic so that data lands in the SIEM in a format detection engineering can rely on;
  • Configuring and integrating EDR/XDR platforms (Microsoft Defender for Endpoint, Cortex XDR, SentinelOne, Microsoft Defender XDR) and cloud platform monitoring (Azure, AWS) into the MSS delivery stack;
  • Supporting the detection engineering team with the platform-side of rule deployment and testing across supported SIEM and EDR/XDR ecosystems;
  • Building automations and integrations on our SOAR platform (XSOAR) and contributing to Core platform (Azure Functions, Durable Task Scheduler, Application Insights, Log Analytics, Bicep-based IaC) that supports our service delivery;
  • Contributing to the evolution of our Self-Service Onboarding capability and service in general
  • Defining high-level engineering patterns and reusable building blocks rather than only point solutions for individual customers;
  • Participating in technical workshops with customers, detection engineers and senior SOC analysts to capture requirements and translate them into implementation plans;
  • Acting as a technical point of reference for junior colleagues, sharing patterns and coaching them on the specifics of MSS engineering;
Requirements

Technical Skills:

  • Hands-on experience with at least one major SIEM platform (Microsoft Sentinel, Elastic, Splunk, or similar), including log source onboarding, parsing/normalization and rule deployment;
  • A solid understanding of SOC operations, incident response workflows and the difference between detection engineering, SOC engineering and SOC analysis;
  • Working knowledge of log forwarding technologies and centralized collector patterns (e.g. Logstash, Elastic Agent, syslog collectors, cloud-native connectors)
  • A strong foundation in Python and/or other relevant scripting or automation languages, and comfort with APIs
  • Practical experience with at least one EDR/XDR ecosystem (Microsoft Defender for Endpoint / Defender XDR, Cortex XDR, SentinelOne) or a desire to specialize in one
  • Familiarity with cloud platforms (Azure and/or AWS) from a security telemetry perspective — audit logs, activity data, identity signals, cloud-native detection tooling;
  • The ability to think beyond individual integrations and contribute to scalable engineering patterns, reusable building blocks and implementation roadmaps;
  • Ideally, exposure to SOAR platforms (XSOAR or similar), case management workflows and playbook development;
  • Ideally, experience with Infrastructure-as-Code (Bicep, Terraform) and Azure-based application components (Azure Functions, Log Analytics, Application Insights).

Soft Skills:

  • Ability to work independently and keep track of your priorities;
  • Strong interpersonal and verbal/written communication skills that enable the ability to work effectively in a collaborative team environment across the entire company;
  • Excellent English communication skills, both verbal and written;
  • A positive, team-oriented and mission-driven attitude;
  • Ability to prepare, document and present your work to colleagues and customers;
  • Comfort in combining strategic thinking with hands‑on implementation.
  • You hold citizenship in one of the 32 NATO member states or the Austrian citizenship;
What do we offer

At NVISO, we care. We are committed to offering you a highly competitive remuneration package including financial and non‑financial components:

  • A training budget of 10.000€ and 10 days every 2 years.
  • Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO, our staff has presented at popular hacking conferences (BlackHat, BruCON, OWASP, etc) and all of our technical staff can acquire deep technical security certifications (GSE, GXPN, GREM, GCFA, OSCP, etc).
  • An entrepreneurial and agile company, where you will be stimulated and supported in driving new initiatives (either through internal innovation or by improving our service offering), without losing sight of having fun!
  • Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team, whose role is to ensure your well‑being and helps you grow in your career!
  • Flexible working model and home office possibilities (+working abroad options).
  • Monthly Allowances;
  • Statutory leave plus 5 additional leave days by NVISO.
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

SOC Automation (Senior) Consultant (m/w/d)
SOC Automation (Senior) Consultant (m/w/d)

Nviso • Brussel Hoofdstad

Hybride
EUR 65 000 - 83 000
SANS training
Training budget 10,000 EUR plus 10 man
Home office possibilities
Senior Incident Response & Digital Forensics Consultant
Senior Incident Response & Digital Forensics Consultant

Nviso • Brussel Hoofdstad

Sur place
EUR 60 000 - 90 000
Training budget of 10.000€ and 10 days every 2 years
Company car and Belgian charging card
Flexible working hours
+1
IT Administrator
IT Administrator

Nviso • Brussel Hoofdstad

Hybride
EUR 55 000 - 70 000
Training budget of 10,000€ every 2 years
Flexible working model
Personal coaching
Junior Security Operations Engineering Consultant (m/w/d)
Junior Security Operations Engineering Consultant (m/w/d)

Nviso • Brussel Hoofdstad

Sur place
EUR 57 000 - 62 000
Training budget
Base salary 57k–62k EUR
Cloud trainings
+8
Chief Information Security Officer
Chief Information Security Officer

Jobtailor • Brussel Hoofdstad

Sur place
EUR 80 000 - 120 000
Flexible working hours
32 days of holiday
Personal coaching
+1
Chief Information Security Officer
Chief Information Security Officer

NVISO Security • Brussel Hoofdstad

Sur place
EUR 120 000 - 160 000
Flexible hours & home office
32 days of holiday
Personal coach
+1
Technical Lead Manager
Technical Lead Manager

NVISO • Brussel Hoofdstad

Sur place
Confidentiel
Training budget 10.000€
Flexible working hours
32 paid leave days
Junior Cyber Architecture & Strategy Consultant — Hybrid
Junior Cyber Architecture & Strategy Consultant — Hybrid

Nviso • Brussel Hoofdstad

Sur place
Junior Penetration Tester
Junior Penetration Tester

Nviso • Brussel Hoofdstad

Sur place
EUR 26 000 - 38 000
Training budget €10k
SANS instructors
Flexible work options
+1
Chief Information Security Officer
Chief Information Security Officer

NVISO • Brussel Hoofdstad

Sur place
Confidentiel
Competitive remuneration package
Flexible working hours
32 days of holiday