You will design and implement SIEM and SOAR solutions while leading the development of detection use cases and response playbooks. Collaborating with Security Operations and international teams is essential for effective integration and continuous improvement.
Anforderungen
- •Experience with leading SIEM and SOAR platforms
- •Strong understanding of log source onboarding
- •Proven ability to design security automation
- •Experience developing detection use cases
- •Strong communication skills in teams
- •Strategic mindset for long-term planning
Deine Aufgaben
- •Design and implement SIEM and SOAR solutions.
- •Lead development of detection use cases.
- •Manage lifecycle of response playbooks.
- •Own roadmap for log source onboarding.
- •Normalize log sources across the enterprise.
- •Collaborate with Security Operations for integration.
- •Engage with international teams and vendors.
- •Drive solution adoption and continuous improvement.
- •Transition into an architectural role with support.
Deine Vorteile
Growth opportunity in supportive environment
Work with cutting-edge technologies
Team of Cyber Defense Leaders
Shape future of cyber defense
Flexible working hours and mobile work
30 days of holidays
Comprehensive training offer
Health days and well-being checks
Company medical care and preventive services
Free gym and sports classes
Discounted meals and campus events
Discounted Jobticket and partner discounts
Good transport connections and free parking
Contribution to company pension
Three daycare centers on campus
Support for holiday camps for children
Original Beschreibung
## Job Description
**About Us:**
Join our dynamic team of Cyber Defense Leaders and become a key player in safeguarding METRO. We are committed to fostering a secure environment where innovation thrives. As a Cyber Defense Leader, you will have the opportunity to grow and develop into a seasoned security practitioner within our company.
**Key Responsibilities:**
* **Architect and Integrate:** Design and implement SIEM and SOAR solutions that align with METRO’s detection, automation, and response strategy.
* **Use Case & Playbook Ownership:** Lead the development and lifecycle management of detection use cases and response playbooks.
* **Log Source Strategy:** Own the roadmap for log source onboarding and normalization across the enterprise.
* **Operational Integration:** Collaborate closely with Security Operations to ensure seamless integration of SIEM/SOAR into daily workflows.
* **Global Collaboration:** Engage with international teams and external vendors to drive solution adoption and continuous improvement.
* **Mentorship and Growth:** Step into an architectural role with support and guidance, even if you're transitioning from a senior engineering position.
## Qualifications
**Qualifications:**
* Experience with at least one leading SIEM and SOAR platform (e.g., Google SecOps, Splunk, Microsoft Sentinel, Cortex XSOAR, etc.).
* Strong understanding of log source onboarding, normalization, and detection engineering.
* Proven ability to design and integrate security automation and orchestration into operational workflows.
* Experience developing and maintaining detection use cases and response playbooks.
* Strong communication skills and experience working in cross-functional, international teams.
* Strategic mindset with the ability to contribute to long-term planning.
**Why Join Us:**
* Opportunity to grow within a supportive and innovative environment.
* Work with cutting-edge technologies and tools.
* Be part of a team of Cyber Defense Leaders that values your contributions and encourages professional development.
* Help shape the future of METRO's cyber defense at a global scale.
## Additional Information
* **Work-life balance:** Flexible working hours with the option of mobile working in agreement with your line manager, 30 days of holidays.
* **Training:** A comprehensive training offer via our own training center or externally.
* **Well-being:** Health days with lots of health checks and information about your well-being, company medical care including a range of preventive services, such as flu shots, OTHEB employee assistance program.
* **Exciting life on campus:** Free gym and sports classes, Rioba coffee bar, canteen with discounted meals for employees, many campus events.
* **Discounts:** discounted Jobticket as well as discounts in our wholesale stores and at many partner companies.
* **Comfort:** Good transport connections, free parking spaces, JobBike.
* **Company pension plan:** You will receive a contribution to your company pension.
* **Family driven:** Three daycare centers for children on campus, support of holiday camps for children of employees.