Left arrow iconBack to search

Security Monitoring Expert (m/f/d) ID27155-2

C4 Energy GmbH & Co. KG
Posted 21 days ago, valid for 8 days
Location

Düsseldorf, Düsseldorf District, North Rhine-Westphalia

Salary

Competitive

Contract type

Contract

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The position of Security Monitoring Expert (m/f/d) requires a minimum of 8 years of experience in cyber defense operations, SOC engineering, or related fields.
  • The role is focused on developing and implementing a short-term security monitoring strategy to detect AI-augmented threats in hybrid Azure and on-premise environments.
  • Candidates should have strong expertise in SIEM, XDR, EDR, and relevant cloud security telemetry, along with a good understanding of Azure security monitoring and attack-chain analysis.
  • The project duration is from September 21, 2026, to March 31, 2027, with a workload of 40 hours per week, and the position is remote.
  • The salary for this role is not explicitly mentioned in the job description.

Security Monitoring Expert (m/f/d) ID27155-2

 

Duration: 21.09.2026 – 31.03.2027

Volumen: 40h/week

Location: remote

 

Please submit your profiles inEnglish!

 

Projectdescription: “Defending the Castle” is the short-term and immediate phase of ourcustomers AI threat resilience response. The purpose is to buy time byincreasing detection, response, containment and recovery readiness while abroader Phase 2 plan is prepared for the rest of the Business IT units.

 

Taskdescription:

-   Conceptual development and structuredimplementation of the short-term security monitoring strategy for “Defendingthe Castle”, focused on detecting AI-augmented threats across hybrid Azure andon-premise environments.

-   Translation of frontier-model driven threatscenarios into actionable detection logic, monitoring requirements, telemetrygaps, alerting rules and escalation criteria.

-   Provision of technical consultation andrecommendations to SOC, Cyber Defense Center, incident response, threatintelligence, cloud, identity, endpoint and platform teams to improve detectioncoverage at machine-speed threat tempo.

-   Definition and validation of monitoring usecases for lateral movement, privilege escalation, identity abuse, cloudcontrol-plane abuse, data staging, exfiltration and persistence across Azurezones and on-premise networks.

-   Production of playbooks, SOPs and tuningguidance that allow monitoring teams to detect, triage and escalate AI-assistedattacks with reduced ambiguity and consistent quality.

-   Establishment and technical definition ofmeasurable detection coverage, alert quality and response-readiness metrics tosupport Q1 2027 completion and readiness for Phase 2.

-   Creation of immediate visibility into themost likely AI-accelerated attack paths affecting identity, cloud, endpoint,network and privileged access layers.

-   Optimization and technical evaluation oftelemetry, correlation, enrichment, and alert prioritization for detectionefficiency.

-   Provision of practical runbooks for SOC andmonitoring teams that can be executed under pressure without relying onindividual tribal knowledge.

-   Conceptual strengthening and technicalenhancement of early-warning capability before a broader business IT resilienceprogramme is launched.

Quality

-   Technical peer review of detection logicacross SOC, incident response and platform functions.

-   Execution and technical documentation ofPurple-team exercises and tabletop scenarios, including simulated alertgeneration and escalation testing.

-   Compilation of an evidence pack containingdetection catalog, data-source matrix, runbooks, tuning history and open riskregister.

-   Preparation of documentation to facilitateoperational sign-off from SOC lead, Cyber Defense lead and relevantAzure/on-prem service owners.

-   Identification and technical gap analysis ofexisting processes (too slow, fragmented, undocumented or dependent on informalknowledge) to document optimization potential.

-   Transformation of risk evaluations intoexecutable playbooks, technical control frameworks, test protocols, backlogitems and management evidence.

-   Provision of a structured handover of aPhase 2 backlog and recommendations for the broader Business IT resilience planafter Q1 2027.

-   Creation of comprehensive documentation withall results regarding the above-mentioned tasks with subsequent handover toUniper for review and approval for further usage.

 

Skills:

Pleasesubmit profiles in english for the Security Monitoring Expert.

 • Minimum 8 years in cyber defense operations,SOC engineering, detection engineering, threat hunting or security monitoring.

•Strong expertise in SIEM, XDR, EDR, Microsoft Sentinel or equivalent platforms,KQL/SPL-style query languages and cloud/security telemetry.

•Good understanding of Azure security monitoring, Entra ID, hybrid identity,endpoint telemetry, network logs, MITRE ATT&CK and attack-chain analysis.

•Experience creating operational runbooks, alert tuning processes and SOCquality metrics.

•Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP orequivalent are beneficial.

 






Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.