SOC Engineer
Job Summary
Who are we
It all starts with the mission: NVISO is here to protect European society from potentially devastating cyber attacks! This means we offer cyber security services to private and governmental organizations to help them better prepare for prevent detect and respond to cyber security incidents.
All of this is built on four fundamental values that define who we are: We are Proud We Break Barriers We Care and No BS!
Tasks
What will you do
As a Senior SOC Engineering Consultant you will help build operate and scale the technical backbone of NVISOs Managed Security Services (MSS). You engineer the platforms integrations and detection infrastructure that our 24x7 Managed Detection & Response service is delivered on across Microsoft Sentinel Elastic Cloud Microsoft Defender XDR Cortex XDR SentinelOne cloud platforms and ICS/OT sensors.
You understand that a modern SOC is only as strong as the telemetry it sees and the platforms it runs on. Your work makes sure that customer log sources are cleanly onboarded that log forwarding infrastructure is fit for purpose that detection content is deployed and tested and that our analysts get high-signal alerts with the context they need to act. As a senior member of the team you go beyond individual integrations - you shape reusable engineering patterns mentor more junior colleagues and act as a technical point of reference in engagements with customers.
You support customers and colleagues by translating operational SOC needs into sustainable engineering strategies and practical implementations covering log onboarding parsing and normalization forwarder deployments SIEM/EDR platform configuration automation and lifecycle management. You have strong communication and interpersonal skills which enable you not only to understand requirements but also to put these requirements into an implementation roadmap explain it to customers and guarantee proper execution. You have an open and approachable mind in line with NVISOs values.
Typical tasks include but are not limited to:
Onboarding new customer log sources into NVISOs SIEM platforms (Microsoft Sentinel Elastic Cloud) preferring native connectors and falling back to customer-hosted NVISO-managed log forwarders where required;
Designing deploying and maintaining log forwarding infrastructure - including load-balanced forwarder clusters - that sits in the customer environment and is operated by NVISO;
Building and maintaining parsers normalization and enrichment logic so that data lands in the SIEM in a format detection engineering can rely on;
Configuring and integrating EDR/XDR platforms (Microsoft Defender for Endpoint Cortex XDR SentinelOne Microsoft Defender XDR) and cloud platform monitoring (Azure AWS) into the MSS delivery stack;
Supporting the detection engineering team with the platform-side of rule deployment and testing across supported SIEM and EDR/XDR ecosystems;
Building automations and integrations on our SOAR platform (XSOAR) and contributing to Core platform (Azure Functions Durable Task Scheduler Application Insights Log Analytics Bicep-based IaC) that supports our service delivery;
Contributing to the evolution of our Self-Service Onboarding capability and service in general
Defining high-level engineering patterns and reusable building blocks rather than only point solutions for individual customers;
Participating in technical workshops with customers detection engineers and senior SOC analysts to capture requirements and translate them into implementation plans;
Acting as a technical point of reference for junior colleagues sharing patterns and coaching them on the specifics of MSS engineering;
Requirements
Technical Skills:
Hands-on experience with at least one major SIEM platform (Microsoft Sentinel Elastic Splunk or similar) including log source onboarding parsing/normalization and rule deployment;
A solid understanding of SOC operations incident response workflows and the difference between detection engineering SOC engineering and SOC analysis;
Working knowledge of log forwarding technologies and centralized collector patterns (e.g. Logstash Elastic Agent syslog collectors cloud-native connectors)
A strong foundation in Python and/or other relevant scripting or automation languages and comfort with APIs
Practical experience with at least one EDR/XDR ecosystem (Microsoft Defender for Endpoint / Defender XDR Cortex XDR SentinelOne) or a desire to specialize in one
Familiarity with cloud platforms (Azure and/or AWS) from a security telemetry perspective audit logs activity data identity signals cloud-native detection tooling;
The ability to think beyond individual integrations and contribute to scalable engineering patterns reusable building blocks and implementation roadmaps;
Ideally exposure to SOAR platforms (XSOAR or similar) case management workflows and playbook development;
Ideally experience with Infrastructure-as-Code (Bicep Terraform) and Azure-based application components (Azure Functions Log Analytics Application Insights).
Soft Skills:
Ability to work independently and keep track of your priorities;
Strong interpersonal and verbal/written communication skills that enable the ability to work effectively in a collaborative team environment across the entire company;
Excellent English communication skills both verbal and written;
A positive team-oriented and mission-driven attitude;
Ability to prepare document and present your work to colleagues and customers;
Comfort in combining strategic thinking with hands-on implementation.
You hold citizenship in one of the 32 NATO member states or the Austrian citizenship;
Benefits
What do we offer
At NVISO we care. We are committed to offering you a highly competitive remuneration package including financial and non-financial components:
- A training budget of 10.000 and 10 days every 2 years.
- Working and learning from the best people in the European cyber security industry. We have multiple SANS Instructors working at NVISO our staff has presented at popular hacking conferences (BlackHat BruCON OWASP etc) and all of our technical staff can acquire deep technical security certifications (GSE GXPN GREM GCFA OSCP etc).
- An entrepreneurial and agile company where you will be stimulated and supported in driving new initiatives (either through internal innovation or by improving our service offering) without losing sight of having fun!
- Our commitment to coach and counsel you and help you grow; each employee receives a personal coach within the team whose role is to ensure your well-being and helps you grow in your career!
- Flexible working model and home office possibilities (working abroad options).
- Monthly Allowances;
- Statutory leave plus 5 additional leave days by NVISO.
IF YOURE INTERESTED PLEASE SEND US YOUR APPLICATION!
WERE LOOKING FORWARD TO MEETING YOU!
Disclaimer on the Use of AI Tools in the Application Process
Please be aware that the creation and submission of application documents (e.g. CV cover letter case studies etc.) using AI-powered tools is only permitted to a limited extent.
Our expectations:
- Application documents must authentically reflect your own qualifications personality and motivation.
- The use of AI for supportive purposes (e.g. spell-checking improving wording) is acceptable.
- Fully generated application documents created by AI without personal adaptation or review are not permitted.
- Under no circumstances may NVISO information data or documents be uploaded to or processed by external AI tools.
We reserve the right to exclude applications from the selection and interview process that are clearly created primarily or exclusively by AI and show no recognizable personal input.
The purpose of this policy is to ensure a fair and transparent recruitment process and to obtain an authentic impression of our applicants.
About Company
We are a young team of cyber security professionals who decided to do things differently. With innovation rooted in our foundations, we offer services that are up against the modern adversary and that help you Prevent, Detect & Respond to cyber attacks. Curious for more? Say hell ... View more