1 день назад
Security Consultant (AI-Driven Threat Management)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Consultant (AI-Driven Threat Management) (Cybersecurity/SIEM): Monitoring and investigating security alerts across cloud and hybrid environments with an accent on threat detection, incident response, and SOC operations. Focus on tuning detection rules, conducting threat hunting and purple teaming, and improving playbooks for cloud infrastructure security.
Location: Budapest, Hungary — Hybrid
Company
is an independent IT consulting and services company founded in Vienna in 1999, delivering innovative IT solutions for international clients across financial services, telecommunications, automotive, and energy.
What you will do
- Monitor and respond to security alerts in a 24/7 security operations environment, including an on-call rotation.
- Perform alert triage, validate events using logs and telemetry, and investigate incidents with system owners and internal stakeholders.
- Escalate confirmed or high-risk incidents to Tier 3 and Incident Response teams with detailed technical findings.
- Develop and tune detection rules, alert logic, and correlation use cases based on real-world threats and the MITRE ATT&CK Framework.
- Conduct threat hunting and purple teaming exercises, including analysis of root causes, lateral movement, and potential data exposure.
- Improve SOC playbooks, incident response procedures, dashboards, metrics, and security response strategies for cloud environments including SAP Cloud Infrastructure.
Requirements
- 2–4 years of experience in a SOC or cybersecurity operations role, preferably in cloud-based or hybrid environments.
- Hands-on experience with public cloud security monitoring and workload protection in Microsoft Azure, AWS, or GCP.
- Experience with alert triage, basic forensic analysis, incident response support, cloud-native security events, and SIEM platforms such as Splunk, Elasticsearch, OpenSearch, or Datadog.
- Knowledge of cloud-native security, networking protocols, Linux internals, security controls, Docker, Kubernetes, MITRE ATT&CK, and the NIST incident handling lifecycle.
- Experience creating or tuning detection rules and using incident handling playbooks, security runbooks, IaC security, and static code analysis tools.
- A bachelor’s degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
Nice to have
- Good scripting and automation skills in Python, PowerShell, or Bash.
- CompTIA Security+, GIAC GSEC/GCIH, EC-Council CEH, or Microsoft SC-200 certification.
Culture & Benefits
- Continuous learning opportunities through diverse client projects.
- Transparent communication and an open-door working environment.
- Supportive team culture focused on honesty, development, and stability.
- Openness to new ideas and modern technologies, including AI-supported hiring tools with final decisions made by humans.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Senior Security Incident Response Analyst (Fintech)
Bitpanda
4 дня назад
Cyber Security Engineer (Crypto)
117 000 - 156 000$
6 дней назад
Cybersecurity Engineer - Internal Security (Cloud/ISO 27001)
6 дней назад
InfoSec Management & Compliance Lead (Cybersecurity)
6 часов назад
Senior Staff GRC Analyst - Strategic Account Partner (Cybersecurity)
3 дня назад
IT Security & Identity Engineer (m/w/d)
3 267€