About this role
Customer-facing role | significant responsibility for implementation, customer communication and service improvement
We are looking for a Senior SOC Analyst (Security & Development) with a strong background in Use-Case Development and Alert Tuning.
You will lead customer workshops and technical meetings in German, analyze their existing environments, and translate business and security requirements into Use-Cases and Detection Rules. In addition to that you will be included in the SOC-Team to have direct impact on operational Analysis work.
• You analyze alerts from heterogeneous ICT infrastructure solutions at our customers, derive necessary measures from them, and provide consulting support during implementation.
• In the case of IT security incidents, you collect, analyze, and document digital evidence and ensure that these incidents are followed up in accordance with internal guidelines and customer requirements.
• By actively optimizing processes and developing automation concepts, you contribute to the continuous improvement of the services provided by our Cyber Defense Center.
• As a technical expert for our SOC solutions, you support our Security Delivery Managers in customer meetings and proactively provide recommendations to improve the customer’s security infrastructure.
• You keep yourself up to date on the latest security solutions available on the market.
Your Profile
• Several years of practical experience in a Security Operation Center, Computer Emergency Response Team, or Computer Incident Response Team
• Knowledge in ICT domains such as networks, security applications and solutions (e.g., firewalls, IDS/IPS), operating systems (Windows, Linux, Unix), and security solutions for IT endpoints; in particular, experience with technologies like Splunk and within the Microsoft Sentinel/Defender environment
• Experience in the development and further development of detection rules and use cases, and in writing KQL/SPL queries
• German skills (C1/C2) to be able to lead workshops, present architectures, and write documentation for German-speaking customers
• English skills (B2+) to collaborate with international teams, read and create technical documentation, and participate in global projects
• Process-oriented working as well as adherence to clear reporting structures and communication channels
• Mandatory Certifications: GCFA (or similar), Microsoft SC-200, Splunk CCDA (or similar)
• Advantagous: Threat hunting experience, experience in vulnerability assessment and additional Blue-Team certifications
Benefits & More
• Flexible working: Home office, remote work, flextime, sabbatical
• 26 vacation days & days off on December 24th and 31st
• Paid lunch break, canteen & vouchers
• Free A1 internet plus additional discounts for family & friends
• Company phone for personal use as well
• Internal job market at A1 & skill enhancement
• A1 Radl – Lease a bicycle or e-bike at affordable rates
For this position, we offer an annual gross salary starting at EUR 80.000 (all-in, 40 hours/week).