Senior SOC Engineer (m/f/d) – Focus SIEM (Splunk / Microsoft Sentinel)

  • q.beyond AG
  • Köln
  • Oberhausen
  • Work experience
  • Senior, very experienced
  • Consulting
  • IT
  • Fulltime
Senior SOC Engineer (m/f/d) – Focus SIEM (Splunk / Microsoft Sentinel), 1. image

JOIN FORCES. MAKE DIGITALIZATION HAPPEN.

q.beyond AG is a leading German IT service provider. Our 1,100 employees with expertise in cloud, SAP, Microsoft, data intelligence, security and software development support our SME customers in their digital transformation.
Design future-proof IT solutions with us as Senior SOC Engineer (m/f/d) – Focus SIEM (Splunk / Microsoft Sentinel) at one of our locations:

  • Köln
  • Oberhausen

YOUR TASKS:

  • Operation, maintenance, and further development of our SIEM landscape (Splunk and Microsoft Sentinel)
  • Development, implementation, and tuning of use cases, correlations, and detection rules
  • Integration of new log sources (e.g., firewalls, EDR, cloud, identity systems)
  • Automation and optimization of processes in security monitoring and incident response
  • Support SOC analysts in investigations and incident handling
  • Contribute to the further development of our use case catalog and detection framework
  • Monitoring, troubleshooting, and performance optimization of the SIEM infrastructure
  • Close collaboration with our analyst team

WHAT WE OFFER YOU:

  • Work-life balance: Flexible mix of working hours and work location (40% home office) for a harmonious work-life integration.
  • Vacation entitlement: 30 days of vacation, special leave and a sabbatical account for restful time off and relaxation.
  • Quality of life: private accident insurance, supplementary health insurance, extended sick pay and a company pension scheme. Focus on your mental health through the Fürstenberg Institute.
  • Fitness promotion: Own JobRad, virtual physiotherapy, various company running events.
  • Career opportunities: Numerous certification opportunities via Udemy, Linkedin Learning and SAP Learning Hub.
  • Professional and personal development: Our internal Academy, monthly company Learning Days, development dialogs and a leadership development program.
  • Family first: Baby welcome package and €1,000 bonus for the birth.
  • Flitzpiepen: Daycare center closed? Don't worry - there are family-friendly workplaces with play facilities for your offspring.
  • Dog Office: Office space where dogs are welcome, for a relaxed working atmosphere.

Some of our benefits are location-based.

WHAT YOU BRING TO THE TABLE:

  • Several years of experience in SOC or SIEM environments
  • Excellent knowledge of Splunk (Search Processing Language, CIM, dashboards, apps)
  • Experience with Microsoft Sentinel and KQL (Kusto Query Language)
  • Solid expertise in onboarding log sources (Syslog, CEF, API, agent-based)
  • Experience in developing detection rules and use cases
  • Good understanding of network, Windows, Linux, and cloud logs
  • Knowledge of scripting/automation (Python, PowerShell, REST API) is an advantage
  • Analytical thinking, structured work approach, and enjoyment of teamwork
  • Fluent in German (C1) and English (B2) 

APPLY QUICKLY. RECEIVE FEEDBACK.

You can apply quickly and easily without a cover letter. Simply upload your CV and certificates online on our job portal.

Inclusion is important to us. We explicitly welcome applications from people with severe disabilities and those with equivalent status.

CONTACT
Your personal contact Rocio will be happy to answer your questions and comments.

q.beyond AG
Talent Acquisition
Rocio Romera del Moral

  • Rocio Romera del Moral
  • Employee

Editorially recommended external content

I agree that external content is displayed to me. This means that personal data is transmitted to third-party platforms. q.beyond AG has no influence on this. You can read more about this in our privacy policy. You can deactivate the display at any time.