Remote Security Engineer – Security Operations Center (REF4455F)

at Deutsche Telekom IT Solutions

Posted 2 days ago 0 applied

Description:

  • Deutsche Telekom IT Solutions is seeking a skilled and security-minded Security Engineer to enhance logging and monitoring capabilities within the Security Operations Center.
  • The role involves designing and maintaining logging infrastructure to ensure visibility across systems and compliance with frameworks such as ISO 27001 and DINS2.
  • Key responsibilities include:
    • Designing, developing, and improving security logging concepts and strategies.
    • Analyzing and assessing existing logging systems and proposing improvements.
    • Integrating and maintaining systems for centralized log collection and processing.
    • Working with Elastic Stack technologies (Elasticsearch, Logstash, Kibana, Beats) for log management.
    • Interpreting and analyzing security logs, events, and incidents in coordination with the SOC team.
    • Ensuring logging solutions meet compliance and regulatory requirements.
    • Collaborating with system owners to onboard new log sources and fine-tune log formats.
    • Writing and maintaining clear documentation in English.
    • Supporting incident response and forensic analysis through effective log availability.

Requirements:

  • Candidates must have experience working in a SOC environment or in a security monitoring/analysis role.
  • A strong understanding of logging technologies, ideally including Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) is required.
  • Familiarity with security logs and event types such as firewall, endpoint, and application logs is necessary.
  • Knowledge of compliance standards and logging requirements, specifically ISO 27001 and DINS2, is essential.
  • The ability to design logging strategies, including what to log, how to process logs, and where/how long to store them, is required.
  • Experience with the technical integration of log sources via syslog, APIs, or agents is necessary.
  • Basic scripting or automation knowledge, such as Bash or Python, is a plus.
  • Strong analytical and problem-solving skills are required.
  • Candidates must be able to work independently and collaboratively in a team.
  • A structured approach to documentation and knowledge sharing is essential.
  • English proficiency is required; German skills are a plus.
  • Experience with SIEM systems (e.g., Splunk, QRadar, Sentinel or similar) is considered a nice to have.

Benefits:

  • The position offers the opportunity to work with a leading employer recognized for its ethical practices and educational cooperation.
  • Employees can benefit from a collaborative and innovative work environment.
  • The company provides opportunities for professional development and skill enhancement.
  • Remote working options are available within Hungary, adhering to European taxation regulations.