Senior Security Engineer (SOC) (m,f,x)

HelloFresh

Berlin (NH)

On-site

USD 103,000 - 148,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Pension scheme (HelloFresh)
Hybrid working model
HelloFresh box discounts
German language learning budget
HelloFresh Academy
Mental health support
Transportation perks
Headspace access
Spill wellbeing platform
Sabbatical leave options

Job summary

HelloFresh in Berlin is seeking an experienced SOC Analyst to join our security operations, mentor junior analysts, and lead incident response while maturing logging, monitoring, and automation across AWS and enterprise IT. You will collaborate with the Manila team, handle escalations, and refine SOC processes for faster containment and reporting.

Ideal candidates bring cloud security monitoring experience, strong scripting skills in Python/Go, and the ability to craft detection rules with AI

Qualifications

  • Proven security monitoring and incident response experience in public cloud environments.
  • Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls.
  • Excellent programming (automation) skill with Python / Go.
  • AI-enhanced coding to write and debug Python scripts for security automation.
  • Ability to write detection rules (Sigma, KQL) with AI tooling.
  • Understanding of network intrusion methods and IDS/IPS concepts.
  • Strong log analysis across multiple sources and noise reduction techniques.
  • Good communication and reporting skills.
  • Willingness to on-call in rotational shifts.

Responsibilities

  • Mature logging and monitoring of Cloud, IT and App workloads using automation and IaC.
  • Ingest and optimize security events from App logs, Kubernetes, CloudTrail, CloudFlare, ELB logs.
  • Conduct threat hunts against file-less malware and APTs using Sysmon, Osquery, RITA, Zeek.
  • Use AI tools to write scripts for security automation and data parsing.
  • Summarize high-volume logs and explain complex code snippets with LLMs.
  • Develop advanced cross-correlation rules beyond out-of-the-box to detect attacks.
  • Generate security metrics and reporting on incidents and SOC effectiveness.
  • Lead incident detection and response in AWS cloud and enterprise IT environments.
  • Act as shift lead and communicate with Berlin SOC leadership during active incidents.
  • Suggest detection rule tuning and SOP refinements; contribute to knowledge base.

Skills

Security monitoring
Incident response
Cloud environments
Python
Go
AI-assisted coding
Detection rules (Sigma/KQL)
Log analysis
Communication skills
On-call readiness

Tools

Sysmon
Osquery
RITA
Zeek
ElasticSearch
Splunk
Sumo Logic
Graylog
KQL
Sigma

Job description

The role

We’re looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh’s security posture.

As an Experienced SOC Analyst at HelloFresh, you’ll bring advanced expertise to our SOC team in Manila. Working in a flat team structure, you’ll act as a Senior Engineer handling escalations from junior analysts, driving complex investigations, and ensuring accurate incident reporting.

You’ll be the point of contact for Berlin SOC leadership during major incidents, mentor junior colleagues, and help refine SOC processes. This is a hands‑on technical role with strong responsibility, requiring both depth in incident response and leadership qualities to keep the operations effective

Above all, we are looking for people who willmake HelloFreshbetter.

What you’ll do
    • Responsible for maturing logging and monitoring of Cloud, IT and Application workloads through automation and IaC
    • Filter, ingest and optimize security-specific events from large log streams such as App logs, Kubernetes logs, CloudTrail, CloudFlare and ELB logs etc.
    • Conduct threat hunts against file-less malware and APTs by leveraging EDR, OS and network telemetry acquired through specialized open-source tool set like Sysmon, Osquery, RITA and Zeek
    • AI-Enhanced Coding: Ability to use AI coding assistants to write scripts for security automation and data parsing and building detection logic.
    • Investigation Acceleration: Proficiency in using LLMs (e.g., Claude, ChatGPT, Gemini) to quickly summarize high-volume JSON logs, investigate and explain complex code snippets etc.
    • Develop advanced correlation and cross-correlation rules beyond what is available out of the box to detect sophisticated attacks and fraud cases
    • Generate security metrics and reporting on incidents and effectiveness of the SOC operation
    • Lead efficient Incident Detection and Response in AWS cloud and enterprise IT environments
    • Shift Communication: Serve as the shift’s main communicator, updating Berlin SOC leadership and local IT/business stakeholders during active incidents.
    • Playbook & Process Improvement: Suggest detection rule tuning, SOP refinements, and contribute to the team knowledge base to reduce false positives and improve workflows.
    • Mentor level (L1) SOC team, conduct purple teaming workshops and participate in CTFs
What you’ll bring
  • Proven security monitoring and incident response experience in public cloud environments
  • Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls
  • Excellent programming (automation) skill with Python / Go
  • Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls
  • AI-Enhanced Coding: Ability to use AI coding assistants to write and debug Python scripts for security automation and data parsing.
  • Detection Logic: Proficiency in writing detection rules (Sigma, KQL) with the assistance of AI tools to optimize query performance and coverage.
  • Understanding of network intrusion methods, network containment, segregation techniques and technologies such as Sandboxes and Intrusion Detection/Prevention Systems (ID/PS)
  • Ability to analyze disparate log sources on demand and cut noise from the signal
  • Good communication and reporting skills
  • Command over log analysis stacks like ElasticSearch, Splunk/SumoLogic, Graylog
  • Open to working on-call in rotational shifts
  • Meeting response time and incident closure metrics, with thorough documentation and timely stakeholder updates.
What we offer

Elevate your lifestyle! Join one of Europe's fastest-growing tech powerhouses in a dynamic phase of expansion.

  • Immerse yourself in a diverse global community of 90+ nationalities.
  • Enjoy a competitive compensation package that goes beyond the norm, with perks like a HelloFresh- subsidized Pension Scheme and a Hybrid working model.
  • Elevate your lifestyle with exclusive discounts on your weekly HelloFresh box and office meals.
  • Invest in your growth with a German language learning budget, and access to the HelloFresh Academy.
  • Plus, we've got your well-being covered with mental health support, transportation perks, and working-parent-friendly benefits. From our 24/7 gym access, wellbeing platforms like Headspace and Spill, to sabbatical leave options, HelloFresh is not just a workplace; it's a lifestyle of perks and possibilities!
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer (SOC) (m,f,x)
Security Engineer (SOC) (m,f,x)

HelloFresh • Berlin (NH)

Hybrid
USD 90,000 - 130,000
HelloFresh Pension Scheme
Hybrid working model
HelloFresh box discounts
+7
Cloud Security Engineer (m,f,x)
Cloud Security Engineer (m,f,x)

HelloFresh • Berlin (NH)

Hybrid
USD 103,000 - 160,000
Hybrid work model
Pension scheme
Discounts on HelloFresh box
+3
FSQA Manager RTE (all genders)
FSQA Manager RTE (all genders)

HelloFresh • City of Amsterdam (NY)

Hybrid
USD 104,000 - 134,000
HelloFresh Pension Scheme
Berlin relocation support
Hybrid working model
+5
Senior Product Manager II, Consumer (all genders)
Senior Product Manager II, Consumer (all genders)

HelloFresh • Berlin (NH)

Hybrid
USD 103,000 - 142,000
Berlin relocation support
Hybrid working model
HelloFresh pension subsidy
Senior Data Platform Engineer, Intelligent Platforms (all genders)
Senior Data Platform Engineer, Intelligent Platforms (all genders)

HelloFresh • Berlin (NH)

Hybrid
USD 170,000 - 210,000
Pension scheme
HelloFresh box discount
Corporate benefits
Senior Security Engineer
Senior Security Engineer

jobr.pro • Town of Greece (NY)

On-site
USD 140,000 - 200,000
Private Medical & Life Insurance
Online mental health platform
Online training platform
+3
[GLOBAL/INT] [MARKETING] Staff Analyst (all genders)
[GLOBAL/INT] [MARKETING] Staff Analyst (all genders)

HelloFresh • Berlin (NH)

Hybrid
USD 103,000 - 154,000
Pension scheme
Berlin relocation support
Hybrid working model
+10
Senior FSQA Manager - PHF (all genders)
Senior FSQA Manager - PHF (all genders)

HelloFresh • City of Amsterdam (NY)

On-site
USD 61,000 - 88,000
Discount on boxes (HelloFresh)
Pension scheme
Gym membership
+6
Senior Safety Specialist
Senior Safety Specialist

Factor_ • Aurora (IL)

On-site
USD 74,813 - 83,125
401(k) company match
Parental leave
Health insurance options
+3
Senior Data Analyst - Operational Excellence
Senior Data Analyst - Operational Excellence

HelloFresh • London (KY)

Hybrid
USD 79,000 - 119,000
HelloFresh employee benefits
70% off HelloFresh/Green Chef boxes
Company pension scheme
+7