Systems Engineer - SOC

Grohe

Deutschland

Vor Ort

EUR 60.000 - 90.000

Vollzeit

14 Tage+
Bewerbungsgenerator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Grohe is seeking a 24x7 SOC and infrastructure support professional to monitor security alerts and incident triage in a global, office-based role. You will analyze logs, investigate indicators, and follow L1 playbooks to resolve routine incidents within defined SLAs.

The role requires 2–5 years in SOC and infrastructure support, strong networking knowledge, and hands-on experience with SIEM and EDR tools. You will collaborate with Tier 2/3 teams and maintain KPI dashboards.

Qualifikationen

  • Bachelor's degree in IT, CS, Cybersecurity or related field.
  • 2–5 years in SOC operations and infrastructure support, with L2 expertise.

Aufgaben

  • Monitor 24x7 security alerts and infrastructure alarms to ensure system availability.
  • Analyze logs and triage security incidents and IT faults to distinguish false positives from threats.
  • Investigate indicators (IPs, hashes, URLs) using threat intel like VirusTotal to rank incidents.
  • Run L1 security playbooks and IT SOPs to resolve routine incidents within SLAs.
  • Document findings in ticketing systems and escalate complex issues to Tier 2/3.

Kenntnisse

SOC operations
L2 security expertise
Networking fundamentals
Incident triage
Windows & Linux command line

Ausbildung

Bachelor's degree in IT / CS / Cybersecurity

Tools

Splunk
Sentinel
QRadar
CrowdStrike
Microsoft Defender
ServiceNow / Jira

Jobbeschreibung

Job description

This is a 6 days working shift based role to provide 24x7 global infrastructure support. This is a work from office role.

Key Responsibilities:
  • Proactively monitor 24x7 security alerts (SIEM) and infrastructure alarms to ensure system integrity and availability.
  • Analyze logs and perform initial triage of security incidents and IT faults to distinguish between false positives and critical threats.
  • Investigate suspicious indicators (IPs, Hashes, URLs) using threat intelligence sources like VirusTotal to prioritize incidents based on severity.
  • Execute L1 security playbooks and IT SOPs/KEDB to resolve routine incidents and service requests within defined SLAs.
  • Document investigation findings accurately in ticketing systems andescalate complex security or infrastructure issues to Tier 2/3 teams.
  • Assist in maintaining monitoring dashboards and generate regular KPI reports on security alert trends and system health.
What We Are Looking For:
  • Minimum 2-5 years of combined experience in SOC operations and Infrastructure support, with specific L2-level expertise..
  • Strong command of networking (OSI, TCP/IP, DNS) and cybersecurity principles (CIA Triad, Cyber Kill Chain, MITRE ATT&CK) to effectively analyze attack vectors.
  • Hands-on experience with SIEM tools (Splunk, Sentinel, QRadar) and EDR solutions (CrowdStrike, Defender) for log analysis, alert monitoring, and incident triage.
  • Proficiency in Windows and Linux command-line navigation with the ability to deeply analyze system logs (Event Viewer, Syslog) for anomalies and suspicious activities.
  • Experience working in a 24x7 rotational shift environment with a strong track record of adhering to SLAs and documenting incidents via tools like ServiceNow or Jira.
  • Excellent problem-solving skills to troubleshoot complex issues across the stack from network packets to VM performance and security alerts.
Good to Have:
  • Valid security credentials (CompTIA Security+, CySA+, BTL1, CEH,CompTIA Network+) are highly preferred
  • Proficiency in scripting languages (Python, PowerShell, PowerCLI, Bash) and automation tools (Ansible, Terraform) to streamline incident response and infrastructure management tasks.
  • Exposure to Cloud Security monitoring (AWS, Azure, GCP) and experience utilizing Threat Intelligence platforms and OSINT for deeper analysis.
  • Foundation level knowledge with additional virtualization, server, network and cloud..
Qualifications
  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

SOC Security Analyst I — Incident Response & SIEM
SOC Security Analyst I — Incident Response & SIEM

CANCOM SE • Deutschland

Remote
USD 70.000 - 90.000
Security Analyst 1st Level (m/f/d)
Security Analyst 1st Level (m/f/d)

CANCOM SE • Deutschland

Vor Ort
USD 70.000 - 90.000
Vulnerability Management / Incident Response Specialist
Vulnerability Management / Incident Response Specialist

Hhw Group • Deutschland

Vor Ort
EUR 70.000 - 90.000
Cyber Incident Handling Analyst
Cyber Incident Handling Analyst

Strategic Resilience Group • Deutschland

Remote
EUR 70.000 - 95.000
Cybersecurity Engineer
Cybersecurity Engineer

Leonardo • Darmstadt

Hybrid
EUR 42.000 - 62.000
Network Security Engineer
Network Security Engineer

Leonardo SpA • Deutschland

Vor Ort
EUR 70.000 - 90.000
Security Operations Engineer (m/f/d)
Security Operations Engineer (m/f/d)

NeuVerge-Tron GmbH • München

Vor Ort
EUR 65.000 - 90.000
Offensive Security Analyst
Offensive Security Analyst

Sonoco • Hub

Vor Ort
EUR 60.000 - 85.000
SOC Analyst
SOC Analyst

Protera • Deutschland

Remote
EUR 70.000 - 100.000
Work from Home setup
Professional development
Certification incentives
Security Architect (m/f/d)
Security Architect (m/f/d)

EPAM Systems • Deutschland

Vor Ort
EUR 90.000 - 150.000