Job Overview
Job description
- Salary:
- EUR 80,000 per year
- Location:
- Berlin, Germany
- Work arrangement:
- On-site
Role Summary
APT-ONE GmbH in Berlin is a consulting firm specializing in cyber security. We effectively protect our customers’ IT, OT, cloud and AI systems from digital threats.
Our approach is different: AI-supported tools handle discovery, routine analysis and pattern recognition - our consultants validate, interpret and focus on strategy and tailor-made solutions. This results in deeper analyzes and a reliable basis for decision-making in a shorter time, with 40-60% less effort for routine work.
AI only with the highest sensitivity for customer data: data protection trumps any gain in efficiency. AI exclusively on contractually secured, data protection-compliant platforms, minimized and anonymized data, never customer data in model training. This approach – and the willingness
We expect all consultants to continually develop our processes and products further with AI.
The focus of this role is detection engineering: SIEM and XDR platforms, log quality, detectionas code and automation - secure in KQL, Sigma and MITER ATT&CK.
Of great advantage
Cloud architect expertise: design, securing and operating cloud and hybrid environments (Azure, AWS, GCP), cloud-native security services, infrastructure-as-code
- Experience with prompt engineering, AI agents or LLM integration into workflows
- Knowledge of AI governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM)
- Experience in regulated environments (CRITIS, financial sector, industry/OT)
OSCP (PEN-200)
SANS / GIAC (Architecture & Tactical Detection)
GCIH (SANS SEC504)
- Additional profile sharpening
- SANS SEC586 (Blue Team Automation)
- Microsoft SC-200
Responsibilities
- Development, operation and further development of SOC platforms (SIEM, SOAR, EDR/XDR)
- Onboarding new log sources including parsing, normalization and ensuring data quality
- Development and optimization of detection rules and use cases (Sigma, KQL, SPL) based on MITER ATT&CK
- Automation of analysis and response processes through playbooks and scripting (Python, PowerShell)
- Building detection-as-code pipelines including versioning, testing and CI/CD
- Integration and operationalization of threat intelligence
- Close collaboration with analysts and incident responders to reduce false positives and improve detection quality
- Technical support for security incidents
- Creation of runbooks, use case documentation and technical concepts
- Use of AI-supported tools for log analysis, rule and playbook drafts as well as documentation – including technical validation and release of the results
Requirements
You've come to the right place if
- you want an attractive fixed salary plus above-average profit sharing.
- you want to work on highly relevant projects in security operations and AI security, regardless of location.
- you see AI as a lever and want to rethink security consulting - without compromising data protection.
- you want to expand your expertise in SOC platforms, detection engineering and automation.
- Confident handling of AI tools in everyday consulting including critical evaluation of the results
- Strong awareness of confidentiality when using AI: You know which data is allowed into which system and know the risks (data leakage, model training, prompt injection)
- Willingness to continuously develop processes and products based on AI
- At least 5 years of experience in IT/cyber security, including several years in architecture or consulting roles
- Broad understanding of technology across network, endpoint, identity, application and cloud
- Experience with zero trust and segmentation concepts as well as IAM/PAM (Entra ID, Active Directory)
- Secure handling of ISO 27001, BSI IT-Grundschutz, NIST CSF, MITER ATT&CK, SABSA/TOGAF
- Knowledge of cryptography, PKI and secure application design
- Fluent German and English skills
Certifications (nice to have)
- OffSec (Hands-on & Offensive/Defensive Integration)
- OSDA (Defense Analyst – SOC-200)
Benefits
- Flexible working hours, remote work, 30 days vacation
- IT equipment such as Apple MacBook
- Regular team events
- Company pension schemes and health insurance, shopping and employee discounts
- Become part of APT-ONE and make security your mission
- Find Jobs in Germany on Arbeitnow
- Role:
- Security Engineer (SOC) (m/w/d)
- Job Type:
- Professionally Experienced