Security Monitoring Expert (m/f/d) ID27155-2
Duration: 21.09.2026 – 31.03.2027
Volumen: 40h/week
Location: remote
Please submit your profiles inEnglish!
Projectdescription: “Defending the Castle” is the short-term and immediate phase of ourcustomers AI threat resilience response. The purpose is to buy time byincreasing detection, response, containment and recovery readiness while abroader Phase 2 plan is prepared for the rest of the Business IT units.
Taskdescription:
- Conceptual development and structuredimplementation of the short-term security monitoring strategy for “Defendingthe Castle”, focused on detecting AI-augmented threats across hybrid Azure andon-premise environments.
- Translation of frontier-model driven threatscenarios into actionable detection logic, monitoring requirements, telemetrygaps, alerting rules and escalation criteria.
- Provision of technical consultation andrecommendations to SOC, Cyber Defense Center, incident response, threatintelligence, cloud, identity, endpoint and platform teams to improve detectioncoverage at machine-speed threat tempo.
- Definition and validation of monitoring usecases for lateral movement, privilege escalation, identity abuse, cloudcontrol-plane abuse, data staging, exfiltration and persistence across Azurezones and on-premise networks.
- Production of playbooks, SOPs and tuningguidance that allow monitoring teams to detect, triage and escalate AI-assistedattacks with reduced ambiguity and consistent quality.
- Establishment and technical definition ofmeasurable detection coverage, alert quality and response-readiness metrics tosupport Q1 2027 completion and readiness for Phase 2.
- Creation of immediate visibility into themost likely AI-accelerated attack paths affecting identity, cloud, endpoint,network and privileged access layers.
- Optimization and technical evaluation oftelemetry, correlation, enrichment, and alert prioritization for detectionefficiency.
- Provision of practical runbooks for SOC andmonitoring teams that can be executed under pressure without relying onindividual tribal knowledge.
- Conceptual strengthening and technicalenhancement of early-warning capability before a broader business IT resilienceprogramme is launched.
Quality
- Technical peer review of detection logicacross SOC, incident response and platform functions.
- Execution and technical documentation ofPurple-team exercises and tabletop scenarios, including simulated alertgeneration and escalation testing.
- Compilation of an evidence pack containingdetection catalog, data-source matrix, runbooks, tuning history and open riskregister.
- Preparation of documentation to facilitateoperational sign-off from SOC lead, Cyber Defense lead and relevantAzure/on-prem service owners.
- Identification and technical gap analysis ofexisting processes (too slow, fragmented, undocumented or dependent on informalknowledge) to document optimization potential.
- Transformation of risk evaluations intoexecutable playbooks, technical control frameworks, test protocols, backlogitems and management evidence.
- Provision of a structured handover of aPhase 2 backlog and recommendations for the broader Business IT resilience planafter Q1 2027.
- Creation of comprehensive documentation withall results regarding the above-mentioned tasks with subsequent handover toUniper for review and approval for further usage.
Skills:
Pleasesubmit profiles in english for the Security Monitoring Expert.
• Minimum 8 years in cyber defense operations,SOC engineering, detection engineering, threat hunting or security monitoring.
•Strong expertise in SIEM, XDR, EDR, Microsoft Sentinel or equivalent platforms,KQL/SPL-style query languages and cloud/security telemetry.
•Good understanding of Azure security monitoring, Entra ID, hybrid identity,endpoint telemetry, network logs, MITRE ATT&CK and attack-chain analysis.
•Experience creating operational runbooks, alert tuning processes and SOCquality metrics.
•Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP orequivalent are beneficial.
Learn more about this Employer on their Career Site
