Deutsche Telekom IT Solutions is seeking a skilled and security-minded Security Engineer to enhance logging and monitoring capabilities within the Security Operations Center.
The role involves designing and maintaining logging infrastructure to ensure visibility across systems and compliance with frameworks such as ISO 27001 and DINS2.
Key responsibilities include:
Designing, developing, and improving security logging concepts and strategies.
Analyzing and assessing existing logging systems and proposing improvements.
Integrating and maintaining systems for centralized log collection and processing.
Working with Elastic Stack technologies (Elasticsearch, Logstash, Kibana, Beats) for log management.
Interpreting and analyzing security logs, events, and incidents in coordination with the SOC team.
Ensuring logging solutions meet compliance and regulatory requirements.
Collaborating with system owners to onboard new log sources and fine-tune log formats.
Writing and maintaining clear documentation in English.
Supporting incident response and forensic analysis through effective log availability.
Requirements:
Candidates must have experience working in a SOC environment or in a security monitoring/analysis role.
A strong understanding of logging technologies, ideally including Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) is required.
Familiarity with security logs and event types such as firewall, endpoint, and application logs is necessary.
Knowledge of compliance standards and logging requirements, specifically ISO 27001 and DINS2, is essential.
The ability to design logging strategies, including what to log, how to process logs, and where/how long to store them, is required.
Experience with the technical integration of log sources via syslog, APIs, or agents is necessary.
Basic scripting or automation knowledge, such as Bash or Python, is a plus.
Strong analytical and problem-solving skills are required.
Candidates must be able to work independently and collaboratively in a team.
A structured approach to documentation and knowledge sharing is essential.
English proficiency is required; German skills are a plus.
Experience with SIEM systems (e.g., Splunk, QRadar, Sentinel or similar) is considered a nice to have.
Benefits:
The position offers the opportunity to work with a leading employer recognized for its ethical practices and educational cooperation.
Employees can benefit from a collaborative and innovative work environment.
The company provides opportunities for professional development and skill enhancement.
Remote working options are available within Hungary, adhering to European taxation regulations.