Security and Threat Operations Engineer

Jobtailor

Deutschland

Remote

EUR 90.000 - 120.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Jobtailor in Germany is seeking an experienced security engineer to build and maintain threat detection, incident response, and vulnerability management across cloud, API, and identity environments. The role emphasizes Python tooling, AI-assisted workflows, and close collaboration with product security to translate risks into production detections.

Ideal candidates will have 5+ years in information security, strong Python skills, and experience with SIEMs and cloud observability (CloudWatch,

Qualifikationen

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response.
  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry.
  • Ability to distinguish attacker behavior from normal production noise.
  • Experience identifying malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.
  • Strong Python programming skills.
  • Experience building and tuning detections in a SIEM or detection platform.
  • Experience with observability and logging systems such as CloudWatch, Datadog, or similar platforms.
  • Experience operating or supporting a vulnerability management program.
  • Familiarity with Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.
  • Experience with at least one major cloud provider, preferably AWS.
  • Working knowledge of identity and access systems and modern authentication flows.
  • Understanding of security implications of internet-facing applications and APIs.
  • Strong understanding of threat modeling, risk prioritization, and practical security controls.
  • Practical experience using AI tools in security workflows.
  • Judgment regarding AI risks including prompt injection, data leakage, excessive tool access, and weak auditability.
  • Excellent analytical, communication, and cross-functional collaboration skills.
  • United States work authorization required
  • Must disclose whether immigration sponsorship is required

Aufgaben

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.
  • Review API, authentication-flow, and WAF traffic patterns to identify malicious activity, abuse patterns, and anomalous behavior.
  • Use AI for triage, analysis, and workflow automation while helping define guardrails for AI-enabled systems.
  • Operate the vulnerability management program by triaging, prioritizing, and driving remediation of findings from Wiz and vulnerability scanning.
  • Develop Python-based tooling and automation for investigations, enrichment, response, and operational scale.
  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.
  • Investigate security events end to end, including triage, scoping, containment support, and remediation follow-through.
  • Support vulnerability management and operational security practices aligned with PCI and SOC 2 expectations.
  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation

Kenntnisse

Threat detection
Incident response
Python programming
Analytical skills
Communication skills
Cross-functional collaboration
Security controls
Threat modeling
API security
Credential attack analysis
AI tools in security workflows
Judgment regarding AI risks

Tools

SIEM
Wiz
CloudWatch
Datadog
Vulnerability scanning tools

Jobbeschreibung

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments
  • Review API, authentication-flow, and WAF traffic patterns to identify malicious activity, abuse patterns, and anomalous behavior
  • Use AI for triage, analysis, and workflow automation while helping define guardrails for AI-enabled systems
  • Operate the vulnerability management program by triaging, prioritizing, and driving remediation of findings from Wiz and vulnerability scanning
  • Develop Python-based tooling and automation for investigations, enrichment, response, and operational scale
  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks
  • Investigate security events end to end, including triage, scoping, containment support, and remediation follow-through
  • Support vulnerability management and operational security practices aligned with PCI and SOC 2 expectations
  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation
Requirements
  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response
  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry
  • Ability to distinguish attacker behavior from normal production noise
  • Experience identifying malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts
  • Strong Python programming skills
  • Experience building and tuning detections in a SIEM or detection platform
  • Experience with observability and logging systems such as CloudWatch, Datadog, or similar platforms
  • Experience operating or supporting a vulnerability management program
  • Familiarity with Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases
  • Experience with at least one major cloud provider, preferably AWS
  • Working knowledge of identity and access systems and modern authentication flows
  • Understanding of security implications of internet-facing applications and APIs
  • Strong understanding of threat modeling, risk prioritization, and practical security controls
  • Practical experience using AI tools in security workflows
  • Judgment regarding AI risks including prompt injection, data leakage, excessive tool access, and weak auditability
  • Excellent analytical, communication, and cross-functional collaboration skills
  • United States work authorization required
  • Must disclose whether immigration sponsorship is required
Core Competencies

Demonstrates expertise in threat detection, incident response, and vulnerability management, with strong proficiency in Python programming and experience in cloud environments. Capable of leveraging AI tools for security workflows and collaborating effectively across teams to enhance security posture.

Highest-signal resume keywords
  • Threat Detection Engineering
  • Python Programming
  • Vulnerability Management
  • Security Incident Response
  • Cloud Security (AWS)
ATS Optimization Keywords
Hard Skills
  • Information Security
  • Threat Detection
  • Incident Response
  • Malicious Activity Identification
  • Detection Tuning
  • AI Tools in Security Workflows
  • Security Controls
  • Threat Modeling
  • API Security
  • Credential Attack Analysis
Soft Skills
  • Analytical Skills
  • Communication Skills
  • Cross-Functional Collaboration
Industry Keywords
  • PCI Compliance
  • SOC 2 Compliance
  • Cloud Security
  • Identity and Access Management
  • Observability
Tools & Technologies
  • SIEM
  • Wiz
  • CloudWatch
  • Datadog
  • Vulnerability Scanning Tools
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Infrastructure and Cybersecurity Analyst
Infrastructure and Cybersecurity Analyst

Jobtailor • Deutschland

Remote
EUR 90.000 - 125.000
Product Security Engineer
Product Security Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Security Automation Engineer
Security Automation Engineer

Jobtailor • Leverkusen

Vor Ort
EUR 80.000 - 130.000
Mid-Level Cybersecurity Analyst
Mid-Level Cybersecurity Analyst

Jobtailor • Deutschland

Remote
EUR 70.000 - 100.000
Senior Security Engineer – Cloud Security
Senior Security Engineer – Cloud Security

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
Staff Engineer – DevSecOps
Staff Engineer – DevSecOps

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Senior Security Agent / AI Red Team Engineer
Senior Security Agent / AI Red Team Engineer

Jobtailor • Deutschland

Hybrid
EUR 103.000 - 142.000
Senior Security Engineer – Sec Ops
Senior Security Engineer – Sec Ops

Jobtailor • Deutschland

Remote
EUR 120.000 - 180.000
VP, Security Technology
VP, Security Technology

Jobtailor • Deutschland

Remote
EUR 150.000 - 230.000