Senior Security Engineer (SOC) (m,f,x)

DUDE CHEM

Berlin

Vor Ort

EUR 90.000 - 130.000

Vollzeit

Vor 2 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Pension scheme
Hybrid working model
Employee discounts

Zusammenfassung

HelloFresh is seeking an Experienced SOC Analyst to join a high-performing SOC team. You will lead investigations, mentor junior analysts, and drive incident response across cloud and on-prem environments.

The role emphasizes proactive improvements to detection, logging, and playbooks while coordinating with Berlin leadership during major incidents. Ideal candidates have cloud security expertise, strong scripting skills in Python/Go, and experience with SIEM/SOAR platforms.

Qualifikationen

  • Proven security monitoring and incident response experience in public cloud environments.
  • Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls.
  • Excellent programming (automation) skill with Python / Go.
  • AI-Enhanced Coding: Ability to use AI coding assistants to write and debug Python scripts for security automation and data parsing.
  • Detection Logic: Proficiency in writing detection rules (Sigma, KQL) with the assistance of AI tools to optimize query performance and coverage.
  • Understanding of network intrusion methods and security containment techniques.

Aufgaben

  • Responsible for maturing logging and monitoring of Cloud, IT and Application workloads through automation and IaC.
  • Filter, ingest and optimize security-specific events from large log streams such as App logs, Kubernetes logs, CloudTrail, CloudFlare and ELB logs.
  • Conduct threat hunts against file-less malware and APTs using EDR, OS and network telemetry.
  • AI-Enhanced Coding: write scripts for security automation and data parsing.
  • Investigation Acceleration: use LLMs to summarize logs and explain code snippets.
  • Develop advanced correlation and cross-correlation rules to detect sophisticated attacks.
  • Generate security metrics and reporting on incidents and SOC effectiveness.
  • Lead Incident Detection and Response in AWS cloud and enterprise IT environments.
  • Shift Communication: update Berlin SOC leadership during active incidents.
  • Playbook & Process Improvement: tune detections and SOPs, expand knowledge base.

Kenntnisse

Security monitoring
Incident response
Cloud SIEM & SOAR
Python
Go
AI-assisted coding
Detection rules
Sigma
KQL
ElasticSearch
Splunk
Graylog
On-call readiness
Communication skills

Tools

ElasticSearch
Splunk
Sumo Logic
Graylog
Sysmon
Osquery
RITA
Zeek
KQL
Sigma

Jobbeschreibung

The role

We're looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh's security posture.

As an Experienced SOC Analyst at HelloFresh, you'll bring advanced expertise to our SOC team in Manila. Working in a flat team structure, you'll act as a Senior Engineer handling escalations from junior analysts, driving complex investigations, and ensuring accurate incident reporting.

You'll be the point of contact for Berlin SOC leadership during major incidents, mentor junior colleagues, and help refine SOC processes. This is a hands-on technical role with strong responsibility, requiring both depth in incident response and leadership qualities to keep the operations effective

Above all, we are looking for people who willmake HelloFreshbetter.We believe there are many different ways of developing skills and we love diverse experiences! So even if you don't "tick all the boxes" but think you'd thrive in this role, we would really like to learn more about you.

What you’ll do
    • Responsible for maturing logging and monitoring of Cloud, IT and Application workloads through automation and IaC
    • Filter, ingest and optimize security-specific events from large log streams such as App logs, Kubernetes logs, CloudTrail, CloudFlare and ELB logs etc.
    • Conduct threat hunts against file-less malware and APTs by leveraging EDR, OS and network telemetry acquired through specialized open-source tool set like Sysmon, Osquery, RITA and Zeek
    • AI-Enhanced Coding: Ability to use AI coding assistants to write scripts for security automation and data parsing and building detection logic.
    • Investigation Acceleration: Proficiency in using LLMs (e.g., Claude, ChatGPT, Gemini) to quickly summarize high-volume JSON logs, investigate and explain complex code snippets etc.
    • Develop advanced correlation and cross-correlation rules beyond what is available out of the box to detect sophisticated attacks and fraud cases
    • Generate security metrics and reporting on incidents and effectiveness of the SOC operation
    • Lead efficient Incident Detection and Response in AWS cloud and enterprise IT environments
    • Shift Communication: Serve as the shift's main communicator, updating Berlin SOC leadership and local IT/business stakeholders during active incidents.
    • Playbook & Process Improvement: Suggest detection rule tuning, SOP refinements, and contribute to the team knowledge base to reduce false positives and improve workflows.
    • Mentor level (L1) SOC team, conduct purple teaming workshops and participate in CTFs
What you’ll bring
  • Proven security monitoring and incident response experience in public cloud environments
  • Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls
  • Excellent programming (automation) skill with Python / Go
  • Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls
  • AI-Enhanced Coding: Ability to use AI coding assistants to write and debug Python scripts for security automation and data parsing.
  • Detection Logic: Proficiency in writing detection rules (Sigma, KQL) with the assistance of AI tools to optimize query performance and coverage.
  • Understanding of network intrusion methods, network containment, segregation techniques and technologies such as Sandboxes and Intrusion Detection/Prevention Systems (ID/PS)
  • Ability to analyze disparate log sources on demand and cut noise from the signal
  • Good communication and reporting skills
  • Command over log analysis stacks like ElasticSearch, Splunk/SumoLogic, Graylog
  • Open to working on-call in rotational shifts
  • Meeting response time and incident closure metrics, with thorough documentation and timely stakeholder updates.
What we offer

Elevate your lifestyle! Join one of Europe's fastest-growing tech powerhouses in a dynamic phase of expansion.

  • Immerse yourself in a diverse global community of 90+ nationalities.
  • Enjoy a competitive compensation package that goes beyond the norm, with perks like a HelloFresh- subsidized Pension Scheme and a Hybrid working model.
  • Elevate your lifestyle with exclusive discounts on your weekly HelloFresh box and office meals.
  • Invest in your growth with a German language learning budget, and access to the HelloFresh Academy.
  • Plus, we've got your well-being covered with mental health support, transportation perks, and working-parent-friendly benefits. From our 24/7 gym access, wellbeing platforms like Headspace and Spill, to sabbatical leave options, HelloFresh is not just a workplace; it's a lifestyle of perks and possibilities!
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Security Engineer (SOC) (m,f,x)
Security Engineer (SOC) (m,f,x)

DUDE CHEM • Berlin

Hybrid
EUR 70.000 - 110.000
Pension scheme
Hybrid work
Box/meal discounts
+6
Senior Cloud Security Engineer (m,f,x) in Berlin
Senior Cloud Security Engineer (m,f,x) in Berlin

HelloFresh SE • Berlin

Hybrid
EUR 90.000 - 130.000
HelloFresh pension scheme
Berlin relocation support
Hybrid working model
+2
Senior Cloud Security Engineer (m,f,x)
Senior Cloud Security Engineer (m,f,x)

DUDE CHEM • Berlin

Hybrid
EUR 90.000 - 120.000
Pension scheme
Berlin relocation support
Hybrid working model
+2
Senior Cloud Security Engineer (m,f,x)
Senior Cloud Security Engineer (m,f,x)

HelloFresh • Berlin

Hybrid
EUR 110.000 - 160.000
Berlin relocation support
Hybrid working model
HelloFresh Academy access
+3
Cloud Security Engineer (m,f,x)
Cloud Security Engineer (m,f,x)

DUDE CHEM • Berlin

Vor Ort
EUR 90.000 - 120.000
Pension Scheme
Hybrid work
Discounts on HelloFresh boxes
+7
Senior GRC Analyst (m,f,x)
Senior GRC Analyst (m,f,x)

HelloFresh SE • Berlin

Vor Ort
EUR 60.000 - 80.000
Pension Scheme
Berlin relocation support
Hybrid working model
+4
Staff Security Engineer (all genders)
Staff Security Engineer (all genders)

HelloFresh SE • Berlin

Hybrid
EUR 75.000 - 100.000
Pension Scheme
Berlin relocation support
German language learning budget
+2
GRC Analyst (m,f,x)
GRC Analyst (m,f,x)

HelloFresh • Berlin

Vor Ort
EUR 50.000 - 70.000
Competitive compensation package
HelloFresh-subsidized Pension Scheme
Berlin relocation support
+7
security engineer
security engineer

Enfint • Berlin

Vor Ort
EUR 120.000 - 160.000
Пенсионная программа
Помощь с переездом в Берлин
Скидки на HelloFresh box и питание в‑о
+3
Senior IT Engineer, MDM Tech (f/m/x)
Senior IT Engineer, MDM Tech (f/m/x)

HelloFresh • Berlin

Hybrid
EUR 90.000 - 130.000
HelloFresh- subsidized Pension Scheme
Berlin relocation support
Hybrid working model
+1