Cybersecurity Operations Engineer (Europe 100% remote)

UBQ.io

Italia

In loco

EUR 70.000 - 90.000

Tempo pieno

40 ore fa
Candidati tra i primi
Generatore di candidature

Una candidatura apposita per questa offerta — un curriculum e una lettera di presentazione personalizzati, perfettamente in linea con l'annuncio.

Supera i filtri ATS

Descrizione del lavoro

UBQ.io is seeking a hands-on Cybersecurity Operations Engineer to implement and optimize core security tech across endpoints, networks, and web apps. You will write detections, investigate incidents, and proactively hunt threats in a fast-paced environment.

The role requires deploying EDR/SSE/SIEM/WAF in production, tuning rules, and collaborating with IT and security teams to improve the organization's security posture.

Competenze

  • 3+ years hands-on experience implementing and managing core security technologies (EDR/SSE/SIEM/WAF).
  • Experience deploying and tuning production security tooling, not just reviewing alerts.
  • SOC experience is a plus if hands-on and engineering-focused, not only monitoring.
  • Hands-on detections work and threat hunting, familiarity with MITRE ATT&CK.

Mansioni

  • Implement, configure, and maintain EDR platforms with policy tuning and response actions.
  • Deploy and manage SSE solutions including SWG and ZTNA.
  • Administer and tune SIEM, onboard log sources, create correlations, dashboards, alerts.
  • Lead evaluation, rollout, and integration of new security tooling with proper docs.
  • Write and tune detections across the stack (EDR, SIEM, WAF) mapping MITRE ATT&CK coverage.
  • Investigate incidents end-to-end: triage, analysis, containment, eradication, post-incident reports.
  • Proactively threat hunt across endpoints, network, and logs to find gaps and create new detections.
  • Develop and maintain runbooks, playbooks, and SOPs; collaborate with IT and infra teams.
  • Support vulnerability management and continuous improvement of security posture.

Conoscenze

EDR
SSE
SIEM
WAF
Threat hunting
Detection tuning
Incident response
Documentation
Zero Trust
MITRE ATT&CK

Formazione

Bachelor's degree in IT / Cybersecurity / CS

Strumenti

EDR platforms
SSE solutions
SIEM
WAF

Descrizione del lavoro

About UBQ.io

UBQ.io is a global technology service provider dedicated to building a more sustainable, independent, and equitable future. We partner with global companies across industries, including AI, blockchain, software, biotech, and education, to transform bold ideas into real, meaningful solutions.

About UBQ.io

UBQ.io is a global technology service provider dedicated to building a more sustainable, independent, and equitable future. We partner with global companies across industries, including AI, blockchain, software, biotech, and education, to transform bold ideas into real, meaningful solutions. Our expertise spans technology consulting, AI and Machine Learning development, Blockchain integration, and global team collaboration. With a worldwide network of specialists, we help organizations stay ahead in a rapidly evolving digital landscape. At UBQ.io, we don’t just advise, we collaborate. Our commitment to innovation, sustainability, and social responsibility guides everything we do as we help clients build technologies that empower people, communities, and industries to thrive.

About The Role

The Cybersecurity Operations Engineer is responsible for the hands‑on implementation, configuration, and optimization of the organization's core security technologies, as well as for writing detections, investigating incidents, and proactively hunting for threats. This role goes beyond monitoring and alerting: the focus is on deploying and tuning the platforms that protect endpoints, network access, web applications, and log data, and on using them to find, understand, and respond to real threats. The ideal candidate has strong technical depth, has personally implemented security tooling in production environments, and thrives in a fast‑paced setting where accuracy, engineering discipline, and security are essential.

Key Responsibilities
  • Implement, configure, and maintain Endpoint Detection and Response (EDR) platforms, including policy tuning, detection rule management, and response actions.
  • Deploy and manage Security Service Edge (SSE) solutions, including Secure Web Gateway (SWG) and Zero Trust Network Access (ZTNA) components.
  • Administer and fine‑tune the Security Information and Event Management (SIEM) platform, including log source onboarding, correlation rule development, dashboards, and alert optimization.
  • Lead the evaluation, rollout, and integration of new security tooling, ensuring proper documentation and alignment with the broader security architecture.
  • Write, test, and tune detection content across the security stack, including SIEM correlation rules, EDR custom detections, and WAF rules, mapping coverage to frameworks such as MITRE ATT&CK.
  • Investigate security incidents end to end, from initial triage through analysis, containment, eradication, and post‑incident documentation, coordinating with relevant teams throughout.
  • Proactively threat hunt across endpoint, network, and log data to uncover suspicious activity that existing detections may have missed, and turn findings into new detections.
  • Develop and maintain technical documentation, standard operating procedures, and incident response and detection playbooks.
  • Collaborate with IT, infrastructure, and application teams to embed security controls and support day‑to‑day operations.
  • Support vulnerability management and drive continuous improvement of the organization's overall security posture.
Requirements
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field (or equivalent practical experience).
  • At least 3 years of hands‑on experience implementing and managing core security technologies such as EDR, SSE, SIEM, and WAF.
  • Demonstrated experience deploying, configuring, and tuning these platforms in production, not only reviewing the alerts they generate.
  • Experience gained in a Security Operations Center (SOC) is a plus, provided it includes hands‑on implementation and engineering work rather than monitoring alone.
  • Hands‑on experience writing and tuning detections, investigating incidents, and conducting threat hunts, ideally with familiarity with the MITRE ATT&CK framework.
  • Excellent understanding of network security, endpoint security, cloud security, and Zero Trust principles.
  • Relevant certifications such as Security+, GCIA, GCIH, OSCP or vendor‑specific credentials are a plus.
  • Strong troubleshooting and problem‑solving skills with a high attention to detail.
  • Ability to handle sensitive information responsibly and securely.
  • Good communication skills and the ability to work effectively across technical and non‑technical teams.
About You

You are a hands‑on security practitioner who enjoys building and strengthening defenses rather than only watching dashboards. You have personally stood up and tuned the tools that keep an organization safe, you write your own detections, and you would rather go hunting for a threat than wait for an alert to tell you it is there. You are structured, reliable, and curious about new technologies, and you enjoy working closely with both technical teams and end users to raise the security bar across the environment.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Cybersecurity Operations Engineer: Threat Hunting
Cybersecurity Operations Engineer: Threat Hunting

UBQ.io • Italia

In loco
EUR 70.000 - 90.000
Principal Security & Detection Engineer
Principal Security & Detection Engineer

Integrity360 • Roma

Ibrido
EUR 90.000 - 130.000
Hybrid work arrangement
Network Security Engineer (Hybrid)
Network Security Engineer (Hybrid)

Quik Hire Staffing • Firenze

Ibrido
EUR 55.000 - 75.000
Network Security Engineer (Hybrid)
Network Security Engineer (Hybrid)

Quik Hire Staffing • Belluno

Ibrido
EUR 45.000 - 70.000
Network Security Engineer (Hybrid)
Network Security Engineer (Hybrid)

Quik Hire Staffing • Savona

Ibrido
EUR 55.000 - 75.000
Information Security Engineer (Tier 3)
Information Security Engineer (Tier 3)

Netrix Global • Lombardia

In loco
EUR 95.000 - 129.000
Network Security Engineer (Hybrid)
Network Security Engineer (Hybrid)

Quik Hire Staffing • Italia

Ibrido
EUR 60.000 - 90.000
Network Security Engineer (Hybrid)
Network Security Engineer (Hybrid)

Quik Hire Staffing • Novara

Ibrido
EUR 55.000 - 85.000
CyberSecurity Specialist
CyberSecurity Specialist

K2 Partnering Solutions • Milano

In loco
EUR 60.000 - 90.000
Network Security Engineer (Hybrid)
Network Security Engineer (Hybrid)

Quik Hire Staffing • Genova

Ibrido
EUR 50.000 - 70.000