Ihre Aufgaben
-
Analysis and assessment of network- and endpoint-based alerts in our customers' infrastructures
-
Derivation of sensible characteristics for automation of alert grouping
-
Continuous improvement of implemented automations and classification mechanisms
-
Preparation of comprehensive situational analysis reports for our customers, alongside with suitable recommendation for their response personnel
-
Tight interaction with the DCSO TI and IR team on specific cases
-
Responsibility for select customers as their focal contact point
-
Coverage not only of solely technical, but also service relevant / business aspects
-
Contribution to overall service development / improvement
Ihr Profil
-
Several years of professional experience in the field of cyber security and practical experience in the field of security incident management
-
Sound understanding of state-of-the-art EDR/XDR solutions
-
Solid understanding of IP networking, network analysis and IDS/IPS approaches
-
Practical experience in presenting incident related information to a diverse audience
-
Very good understanding of nowadays cyber threats and typical techniques used by adversaries
-
Sound knowledge of the MITRE ATT&CK framework and experience with its application to routine SOC tasks
-
Fluent in English, both, verbally and in writing
-
Experience with / good knowledge of Splunk would be a plus
-
Experience with / knowledge of the OSS IDS Suricata and respective rule writing would be a plus
*Courage to leave a gap: You don't meet our requirements completely? We are still looking forward to your application!
Wir bieten Ihnen
Best Place to Work
-
Culture International team Company events Close team atmosphere Culture of trust Openness and transparency
-
Modern Work Environment Trust-based flex time Remote work Part-time schedules Ergonomic office equipment Accessibility "Bring-your-dog" Sabbaticals
-
Feel good Fruit and vegetables Diverse selection of drinks Daily food allowance Health care Subsidy Urban Sports Club Language courses with Babbel voiio - Employee Assistance Program
-
Financials Market-competitive salary 30 days of vacation Closed on 24th and 31st December Employer-funded pension Continuing education and conferences Holiday-subsidy voluntary service Subsidy BusinessBike Subsidy "Deutschlandticket Job" Shopping discount via Corporate Benefits
The Job
Kontakt
DCSO Deutsche Cyber- Sicherheitsorganisation GmbH
EUREF-Campus 22 10829 Berlin
info@dcso.de +49 30 726219-0