Security Operations Engineer II (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Operations Engineer II (Cybersecurity): Handling end-to-end incident response and threat management for enterprise software with an accent on triage, containment, and remediation. Focus on automating SecOps tasks using a DevOps mindset and integrating security tooling via APIs.
Location: Bucharest, Romania (Hybrid, office-based, or remote flexibility depending on the team)
Company
is a leading enterprise software company specializing in AI-powered automation and Robotic Process Automation (RPA).
What you will do
- Own security incidents end-to-end, from real-time triage of SIEM, EDR, and cloud telemetry to containment and eradication.
- Conduct root cause analysis to develop durable detections and controls that prevent incident recurrence.
- Perform proactive threat hunting across enterprise and cloud environments to mitigate threats before they manifest.
- Develop and maintain incident response playbooks and runbooks, exercising them through drills and tabletops.
- Manage and tune the detection and response tooling stack (SIEM, EDR, SOAR) and contribute to configuration standards.
- Automate routine SecOps tasks using a DevOps/IaC mindset and integrate security tooling via APIs.
Requirements
- Minimum 3 years of experience in Security Operations roles (SOC analyst, incident responder, or threat hunter).
- Strong working knowledge of NIST 800-61, SANS PICERL, and MITRE ATT&CK frameworks.
- Deep understanding of OS internals (Windows, Linux, macOS), networking protocols, and cloud platforms, preferably Azure.
- Hands-on experience with major SIEMs (e.g., Sentinel, Splunk) and EDRs (e.g., Defender XDR, CrowdStrike).
- Working scripting ability in Python, PowerShell, Bash, or Node.
- Ability to author KQL queries and experience using LLM-based coding agents (e.g., Claude Code, Copilot, Cursor).
Culture & Benefits
- Flexibility in when and where work gets done, with varying hybrid and remote options per team.
- Inclusive workplace that values diverse backgrounds, experiences, and ideas.
- Growth-oriented environment for curious, self-propelled, and genuine professionals.
- Commitment to equal opportunity and reasonable accommodations for all candidates.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →