Security Operations Engineer

Relocation
Apply
AI Summary

Join gmx, web.de & mail.com as a Security Operations Engineer to enhance cybersecurity operations. Responsibilities include threat hunting, incident response leadership, and workflow automation. Requires a technical degree or equivalent, hands-on cybersecurity experience, and strong technical foundations.

Key Highlights
Lead incident response and manage security alerts.
Design and improve SIEM, threat intelligence, and forensics processes.
Automate detection and response workflows using scripting and playbooks.
Key Responsibilities
Design and continuously improve processes and tools in key areas such as SIEM, cyber threat intelligence, threat hunting, vulnerability management, and digital forensics.
Triage security alerts and take the lead as Incident Manager / Commander during confirmed incidents, coordinating cross-functional teams under pressure.
Automate detection and response workflows, leveraging established platforms like SIEM or EDR/XDR, as well as your own custom scripts and playbooks.
Perform in-depth technical analyses, including log analysis and digital forensics.
Participate in our on-call rotation, ensuring 24/7 security coverage when needed.
Technical Skills Required
SIEM Cyber Threat Intelligence Vulnerability Management Digital Forensics Log Analysis Python Git NIST FIRST MITRE ATT&CK DevSecOps Continuous Delivery Detection as Code Infrastructure as Code
Benefits & Perks
Internal and external training opportunities
LinkedIn Learning
Language courses
Talent development programs
Conferences
Mentoring
Linux, Mac, or Windows choice
Slack days
Lecture series
Courses
Open-source projects
Community meetups
User groups
Wellpass
Free internal sports and fitness classes
Health days
Family & care support services
Discounts at fitness centers
Mental health first responder
Fresh fruit and drinks
Subsidy for job bike leasing
Job ticket
Relocation service
Home office options
Flexible working hours
30 days of vacation
Option for additional unpaid leave
Corporate benefits
Company pension scheme
Capital-forming benefits
Occupational disability insurance
Partner discounts
Summer and winter parties
Sports tournaments
Team events
Nice to Have
Relevant certifications (e.g., OSCP, GCIA, GCIH) are a plus, but not required.
Solid Python knowledge is a plus.

Job Description


Your Tasks

Are you passionate about cybersecurity and blue team topics like threat hunting, anomaly detection, and incident response? Do you thrive in an agile environment and want to contribute to a leading digital company? Join us as a Security Operations Engineer and help secure our products: WEB.DE, GMX, and mail.com! In this role, you’ll be at the heart of our operational security:


  • Innovate and Enhance: Design and continuously improve processes and tools in key areas such as SIEM, cyber threat intelligence, threat hunting, vulnerability management, and digital forensics – helping us maintain a real-time understanding of our threat landscape.
  • Lead Incident Response: Triage security alerts and take the lead as Incident Manager / Commander during confirmed incidents, coordinating cross-functional teams under pressure.
  • Automate Workflows: Automate detection and response workflows, leveraging established platforms like SIEM or EDR/XDR, as well as your own custom scripts and playbooks.
  • Technical Analysis: Perform in-depth technical analyses, including log analysis and digital forensics.
  • 24/7 Coverage: Participate in our on-call rotation, ensuring 24/7 security coverage when needed.


Your Profile

Do you have a technical degree or equivalent education, and a passion for cybersecurity? Have you already gained hands-on experience in the field? Then we’re looking forward to your application!


  • Expertise: Strong knowledge of common security operations tools and processes—such as SIEM, cyber threat intelligence, vulnerability management, or forensic tools—and staying current with best practices and standards (e.g., NIST, FIRST, MITRE ATT&CK). Relevant certifications (e.g., OSCP, GCIA, GCIH) are a plus, but not required.
  • Technical Foundation: Solid technical foundation with a deep understanding of networks, communication protocols, operating systems, and web-based distributed architectures.
  • Continuous Learning: Commitment to continuous learning and regularly sharpening your skills in IT infrastructure and security. Familiarity with modern practices such as DevSecOps, Continuous Delivery, Detection as Code, or Infrastructure as Code.
  • Hands-On Skills: Comfortable writing scripts or code in at least one language (solid Python knowledge is a plus) using Git-based workflows.
  • Team Player: Excellent communication skills (English level at least C1) and the ability to guide and align stakeholders.


Our Benefits

🏢 Lived corporate culture: Flat hierarchies, a culture of respect and appreciation, signatories of the Diversity Charter, open communication, and no dress code.

🎓 Wide range of further training: Internal and external training opportunities, LinkedIn Learning, language courses, talent development programs, conferences, and mentoring.

💡 TEC-Campus: Free choice between Linux, Mac, or Windows, slack days, conferences, lecture series, courses, open-source projects, community meetups, and user groups.

❤️ Active health care: Wellpass, free internal sports and fitness classes, health days, family & care support services, discounts at fitness centers, mental health first responder, fresh fruit, and drinks for free.

🚝 Mobility: Subsidy for job bike leasing, job ticket, and relocation service if you live outside Germany.

💻 Flexible working models: Home office options, flexible working hours, and 30 days of vacation with the option for additional unpaid leave.

💰 Financial benefits: Corporate benefits, company pension scheme, capital-forming benefits, occupational disability insurance, and various partner discounts.

🎉 Events: Summer and winter parties, sports tournaments, and team events.


Reference ID: 350


Similar Jobs

Explore other opportunities that match your interests

Senior IT Security Engineer

Cyber Security
2d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Trade Republic

Germany

IT Security Operations Technician

Cyber Security
2d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Starion

Germany

IT Security Engineer

Cyber Security
4d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Associate

nvision quantum technologies

Germany

Subscribe our newsletter

New Things Will Always Update Regularly