Talent.com
Senior Security Operations Center Analyst (f/m/d)
Senior Security Operations Center Analyst (f/m/d)Thinkproject • München, DE
Senior Security Operations Center Analyst (f / m / d)

Senior Security Operations Center Analyst (f / m / d)

Thinkproject • München, DE
Vor 30+ Tagen
Stellenbeschreibung

Introducing Thinkproject Platform

Pioneering a new era and offering a cohesive alternative to the fragmented landscape of construction software, Thinkproject seamlessly integrates the most extensive portfolio of mature solutions with an innovative platform, providing unparalleled features, integrations, user experiences, and synergies.

By combining information management expertise and in-depth knowledge of the building, infrastructure, and energy industries, Thinkproject empowers customers to efficiently deliver, operate, regenerate, and dispose of their built assets across their entire lifecycle through a Connected Data Ecosystem.

What your day will look like

We are looking for a highly experienced and technically skilled Senior Security Operations Centre (SOC) Analyst to join our team and play a key role in identifying, investigating, and responding to advanced security threats, issues and vulnerabilities across our organization. This role requires deep expertise in monitoring and securing endpoints, networks, cloud platforms, applications, and infrastructure, with the ability to manage complex incidents independently and drive continuous improvement within the SOC function.

As a senior member of the team, you will lead investigations into sophisticated threats such as advanced persistent threats (APTs), malware outbreaks, and targeted attacks. You will perform hands-on analysis of security events, including forensic evidence collection and root cause analysis, and contribute to the development of detection capabilities across SIEM, EDR, and other monitoring tools.

You will actively engage in threat hunting, leveraging your deep understanding of application code, infrastructure and hosting architectures (cloud and on-premise), the software development lifecycle (SDLC), and CI / CD pipeline solutions to identify risks that span traditional and cloud-native environments. You will also play a key role in implementing and refining automation and playbooks utilising SOAR platforms to accelerate response efforts and reduce operational overhead.

The ideal candidate will have a strong technical foundation and a proactive mindset, with a passion for staying ahead of current and emerging threats. You will collaborate closely with IT, DevOps, and application teams to improve detection coverage, enhance SOC processes, and ensure security operations are aligned with industry best practices and compliance requirements.

This role encompasses reactive incident response, proactive detection engineering, threat hunting, and vulnerability management. You will also contribute to strategic initiatives including penetration testing coordination, security assessments, and audit preparation, while mentoring analysts, sharing threat intelligence insights, and maintaining SOC documentation and workflows.

This role sits within the Product Operations and Corporate IT branch, reporting to the Director of Cyber Security and Networking, and operates as part of the broader Cyber Security, Network, and Security Engineering teams.

Main responsibilities :

  • Independently investigate and respond to security alerts and events from SIEM, EDR, and other security tools across endpoints, networks, cloud platforms, and applications.
  • Lead proactive threat hunting activities, leveraging threat intelligence, application logs, and infrastructure telemetry to uncover indicators of compromise or stealthy threat activity.
  • Perform in-depth analysis of logs, API configurations and traffic, container environments, network data, application and infrastructure architecture, as well as data center hosting environments to support threat detection, incident investigation, and root cause analysis.
  • Manage complex cybersecurity incidents end-to-end, including containment, eradication, recovery, and post-incident analysis, while coordinating closely with cross-functional stakeholders.
  • Deploy, operate, configure, and tune SIEM platforms and detection tools to enhance signal accuracy, reduce alert fatigue, and maintain effective detection coverage.
  • Design, build, and maintain incident response playbooks and automation workflows to increase the efficiency, speed, and consistency of incident response processes.
  • Simultaneously manage multiple active investigations and day-to-day SOC operations, effectively prioritising tasks and managing time under pressure.
  • Conduct forensic analysis during investigations, including evidence preservation, malware analysis, memory examination, and root cause identification.
  • Collaborate with DevOps, IT, and development teams to ensure timely containment, mitigation, and remediation of vulnerabilities and threats.
  • Coordinate outputs from security assessment tools and penetration tests, ensuring clear ownership and timely closure of identified issues.
  • Participate in and lead security testing exercises to evaluate and strengthen detection capabilities and response procedures.
  • Drive continuous improvement of SOC operations by identifying logging gaps, proposing monitoring enhancements, and introducing new detection or response technologies.
  • Maintain comprehensive documentation of investigations, incidents, tuning efforts, and threat intelligence to support reporting, knowledge sharing, and audit readiness.
  • Stay current with evolving threat landscapes, adversary techniques, and emerging security tools and practices to strengthen SOC capabilities.
  • Adapt SOC processes, solutions, and procedures to enhance the monitoring of the organization's IT network health.
  • Ensure security operations and incident response practices are aligned with industry-recognised frameworks such as ISO 27001.
  • Implement solutions within CI / CD pipelines to identify and block security issues reaching production environments
  • Support the development and refinement of SOC procedures, training materials, and operational standards to enhance maturity and consistency across the team.

What you need to fulfill the role

You Must Have :

Language & Communication

  • Proficiency in spoken and written English, with the ability to communicate effectively across both technical and non-technical audiences
  • The ability to communicate difficult or sensitive information tactfully
  • Education & Experience :

  • A bachelor’s degree in Cyber Security or a related field, or equivalent professional experience
  • Strong knowledge of cybersecurity principles, threat landscapes, and incident response procedures
  • Awareness of current and emerging cyber threats affecting SaaS organisations
  • Technical Skills :

  • Hands-on experience with implementation, ongoing management and maturing of Security Information and Event Management (SIEM) tools, Endpoint Detection and Response (EDR) platforms, threat intelligence platforms, and vulnerability identification tools
  • Experience integrating custom-built applications into SIEM platforms
  • Experience with implementation of automation solutions, enhancing SOC efficiency and speeding incident response
  • Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms, including developing and maintaining automated response playbooks
  • Experience with threat hunting focused on application code, application, infrastructure and hosting architecture, leveraging coding skills and a solid understanding of the software development lifecycle (SDLC) and infrastructure components
  • Experience managing security issues identified through internal tools and external assessments, ensuring remediation is completed in line with company policies and standards
  • Knowledge of common security frameworks and best practices
  • Experience implementing solutions to detect and block security risks in CI / CD pipelines to prevent vulnerable code from being deployed into production
  • SOC Operations :

  • Experience in complex incident response and investigation, including forensic evidence handling and root cause analysis
  • Experience managing business-as-usual (BAU) security operations workload alongside project-based work, both independently and in coordination with other team members
  • Experience managing outputs from cybersecurity assessment tools, coordinating timely mitigation and remediation with key stakeholders.
  • Experience coordinating outsourced penetration tests, ensuring smooth execution without service disruption
  • Experience conducting security assessment exercises to evaluate SOC operational effectiveness and the organisation’s ability to respond to cybersecurity incidents
  • Experience in tuning detection rules and alerts to improve accuracy and reduce false positives in security monitoring
  • Technical Expertise :

  • Experience with Azure, Azure AD, and AWS technologies and services
  • Experience conducting forensic analysis of cybersecurity incidents
  • Teamwork & Leadership :

  • A positive, self-motivated attitude
  • The ability to work effectively in a team environment, collaborating with cross-functional teams to achieve shared objectives
  • Strong time management and prioritisation skills, with the ability to manage your own workload
  • The ability to perform effectively under pressure, prioritise tasks, and make sound decisions in high-stress or emergency situations
  • A proactive mindset with the ability to critically evaluate your own work, identify improvement opportunities, and automate, simplify, or standardise processes where appropriate
  • It Would Be Good to Have :

    Language Skills :

  • Proficiency in German (spoken and written)
  • SOC Operations

  • Experience conducting red or purple team exercises to validate detection capabilities and improve response playbooks
  • Familiarity with security operations in containerised environments and microservices architectures (e.g., Kubernetes, Docker)
  • Technical Skills :

  • Understanding of advanced detection engineering techniques, such as creating custom correlation rules and behavioural analytics in SIEM platforms
  • Exposure to secure software development practices and security testing of APIs, containers, and cloud-native applications
  • Experience conducting both external and internal penetration testing of applications and infrastructure.
  • Technical Expertise :

  • Experience with Microsoft Sentinel SIEM Solutions
  • Experience working within a SaaS or software-driven organisation, particularly in multi-tenant or cloud-native environments
  • Experience with AI technologies, including understanding the cybersecurity threats they pose to organizations and how they can be leveraged to enhance operational effectiveness.

    What we offer

    Lunch 'n' Learn Sessions I Women's Network I LGBTQIA+ Network I Coffee Chat Roulette I Free English Lessons I Thinkproject Academy I Social Events I Volunteering Activities I Open Forum with Leadership Team (Tp Café) I Hybrid working I Unlimited learning

    We are a passionate bunch here. To join Thinkproject is to shape what our company becomes. We take feedback from our staff very seriously and give them the tools they need to help us create our fantastic culture of mutual respect. We believe that investing in our staff is crucial to the success of our business.

    Jobalert für diese Suche erstellen

    Fmd • München, DE

    Ähnliche Stellen
    SWE Security Advisor (m / w / d)

    SWE Security Advisor (m / w / d)

    BWI GmbH • bundesweit, Bonn, Frankfurt, Hamburg, München, Nürnberg, Berlin, Leipzig
    Kolleg •innen betreiben und modernisieren wir eine der größten und komplexesten IT-Infrastrukturen in Deutschland.Sorge gemeinsam mit uns für die digitale Zukunftsfähigkeit der Bundeswehr.Vollzeit i...Mehr anzeigen
    Zuletzt aktualisiert: vor 7 Tagen • Gesponsert
    Core Application Specialist / Manager Datenintegrationen (m / w / d)

    Core Application Specialist / Manager Datenintegrationen (m / w / d)

    Messe München GmbH • München
    Erlebnisse und inspirierende Begegnungen.Messe München hin zu einer modernen und zukunftsträchtigen.Reizt Sie ein anspruchsvolles Arbeitsumfeld im Bereich des IT-Betriebs? Dann heißen wir Sie herzl...Mehr anzeigen
    Zuletzt aktualisiert: vor 1 Tag • Gesponsert
    Datacenter Security Specialist – Schwerpunkt Netzwerk und Firewalling (m / w / d)

    Datacenter Security Specialist – Schwerpunkt Netzwerk und Firewalling (m / w / d)

    Anstalt für Kommunale Datenverarbeitung in Bayern (AKDB) • Augsburg, Bayreuth, Chemnitz, Landshut, München, Nürnberg, Regensburg, Würzburg
    Datacenter Security Specialist – Schwerpunkt Netzwerk und Firewalling (m / w / d).Wir machen Deutschlands Verwaltung digital. Ver­waltung, die das Mit­einander von Bürger : innen und Verwaltungen in Städt...Mehr anzeigen
    Zuletzt aktualisiert: vor 2 Tagen • Gesponsert
    Information Security Manager (m / w / d) - Projektmanagement, IT-Security, Ingenieur

    Information Security Manager (m / w / d) - Projektmanagement, IT-Security, Ingenieur

    Proliance • München, DE
    ISO / IEC 27001, NIS-2, TISAX, BSI IT-Grundschutz).Gap-Analysen & Projektsteuerung : Durchführung von Reifegradanalysen, Planung geeigneter Maßnahmen und Begleitung bis zur erfolgreiche...Mehr anzeigen
    Zuletzt aktualisiert: vor über 30 Tagen • Gesponsert
    Datacenter Security Specialist – Schwerpunkt Netzwerk und Firewalling (m / w / d)

    Datacenter Security Specialist – Schwerpunkt Netzwerk und Firewalling (m / w / d)

    Öffentlicher Dienst & Verbände Karriere • München, Germany
    Datacenter Security Specialist – Schwerpunkt Netzwerk und Firewalling (m / w / d).Mehr anzeigen
    Zuletzt aktualisiert: vor 23 Stunden • Gesponsert
    Senior Backup & Data Protection Specialist (m / w / d) - System Engineering / Admin, Ingenieur

    Senior Backup & Data Protection Specialist (m / w / d) - System Engineering / Admin, Ingenieur

    CompuSafe Data Systems AG • München, DE
    Diese Tätigkeiten kommen auf Dich zu : .Analyse, Bewertung und Optimierung von technischen Unterlagen, Dokumentationen und Architekturvorgaben. Durchführung von Abnahmen, Einsatzprüfung...Mehr anzeigen
    Zuletzt aktualisiert: vor 1 Tag • Gesponsert
    Information Security Program Manager (m / w / d) - Projektmanagement, IT-Security, Ingenieur

    Information Security Program Manager (m / w / d) - Projektmanagement, IT-Security, Ingenieur

    Allianz in Deutschland • Unterföhring, DE
    Die CIS-Funktion bei Allianz Technology trägt dazu bei, die digitalen Vermögenswerte der Organisation zu schützen, das Vertrauen der Kunden zu bewahren und die Geschäftskontinui...Mehr anzeigen
    Zuletzt aktualisiert: vor 1 Tag • Gesponsert
    IT-Netzwerk und Security Administrator (m / w / d) Schwerpunkt SIEM-Lösung

    IT-Netzwerk und Security Administrator (m / w / d) Schwerpunkt SIEM-Lösung

    KNDS • München
    KNDS Deutschland entwickelt, fertigt und betreut als Systemhaus ein breit gestreutes Produktportfolio.Dazu zählen Kampfpanzer, hochgeschützte Radfahrzeuge, Artilleriesysteme, Militärbrücken, Kunden...Mehr anzeigen
    Zuletzt aktualisiert: vor 5 Tagen • Gesponsert
    (Senior) Integration Specialist

    (Senior) Integration Specialist

    GermanTechJobs Talents • Bad Tölz, Germany
    Deutsch (Muttersprache) + Englisch C1.Starke JavaScript-Kenntnisse fr Tagging / Event-Tracking.Praxiserfahrung mit Website- oder Shop-Integrationen und Analytics-Tools (z. Erfahrung mit APIs, Webhooks...Mehr anzeigen
    Zuletzt aktualisiert: vor 25 Tagen • Gesponsert
    IT-Security Analyst / Engineer (m / w / d)

    IT-Security Analyst / Engineer (m / w / d)

    Fonds Finanz Maklerservice GmbH • München
    Komm zur Fonds Finanz, Deutschlands führendem Allfinanz-Maklerpool – und erlebe ein motivierendes Arbeitsumfeld mit offener Unternehmenskultur, großen Gestaltungsfreiräumen, spannenden Aufgaben und...Mehr anzeigen
    Zuletzt aktualisiert: vor 3 Tagen • Gesponsert
    Identity Access Management (IAM) Specialist – IT-Governance & Security (m|w|d)

    Identity Access Management (IAM) Specialist – IT-Governance & Security (m|w|d)

    Münchener Hypothekenbank eG • München
    Die Münchener Hypothekenbank ist eine eigenständige und auf dem nationalen wie internationalen Markt erfolgreiche Immobilienbank. Wir sind spezialisiert auf die langfristige Finanzierung von Wohn- u...Mehr anzeigen
    Zuletzt aktualisiert: vor 7 Tagen • Gesponsert
    Datacenter Admin (m / w / d)

    Datacenter Admin (m / w / d)

    dbs Delta Business Service GmbH • Poing, Bayern, Deutschland
    Delta Business Service GmbH is a consulting and service company for industrial production and service companies.As an in-house consultant, we advise REMA TIP TOP AG and numerous other companies.For...Mehr anzeigen
    Zuletzt aktualisiert: vor 27 Tagen • Gesponsert
    Team Lead (m / w / d) – Expert Support Center

    Team Lead (m / w / d) – Expert Support Center

    Bertrandt AG • München
    Der Bertrandt-Konzern bietet seit über 50 Jahren Entwicklungslösungen für die internationale Automobil- und Luftfahrtindustrie sowie die Branchen Maschinen- und Anlagenbau, Energie, Medizintechnik ...Mehr anzeigen
    Zuletzt aktualisiert: vor 2 Stunden • Gesponsert • Neu!
    Security und Export Control Specialist (m / w / d)

    Security und Export Control Specialist (m / w / d)

    EUROJET Turbo GmbH • Hallbergmoos, DE
    EUROJET Turbo GmbH ist das internationale Managementkonsortium für das Turbofan Triebwerk EJ200, das für das größte gemeinschaftliche europäische Eurofighter / Typhoon Programm entwickelt wurde.Der F...Mehr anzeigen
    Zuletzt aktualisiert: vor 7 Tagen • Gesponsert
    Segment Entwickler für Industrial Energy Solutions / Data Center (w / m / d)

    Segment Entwickler für Industrial Energy Solutions / Data Center (w / m / d)

    E.ON Energy Projects GmbH • München, DE
    Seit 2000 haben wir Projekte mit einer elektrischen Leistung von über 1 Gigawatt in ganz Europa realisiert.Mit unseren maßgeschneiderten, ganzheitlichen Lösungen treiben wir die Dekarbonisierung un...Mehr anzeigen
    Zuletzt aktualisiert: vor 4 Tagen • Gesponsert
    Cyber Security Specialist (m / w / d)

    Cyber Security Specialist (m / w / d)

    Telair International GmbH • Miesbach (Nahe Holzkirchen und Rosenheim), DE
    Gemeinsam die Luftfahrt von morgen gestalten!.Als Teil eines global agierenden Konzerns, gehören wir zu den weltweit führenden Unternehmen in der Entwicklung und Produktion innovativer Frachtlösung...Mehr anzeigen
    Zuletzt aktualisiert: vor 7 Tagen • Gesponsert
    Cyber Security Analyst & Engineer (m / w / d)

    Cyber Security Analyst & Engineer (m / w / d)

    Iconic Heads GmbH • Munich, BY, de
    Quick Apply
    Cybersecurity Analyst & Engineer.Diese Rolle richtet sich an Security-Expert : innen, die.Security Engineering verbinden möchten – mit klarem Fokus auf Detection, Automatisierung und Weiterentwic...Mehr anzeigen
    Zuletzt aktualisiert: vor 5 Tagen
    (Senior) Manager Cyber Security (Financial Services) (w / m / d) - Projektmanagement, IT-Security, Ingenieur

    (Senior) Manager Cyber Security (Financial Services) (w / m / d) - Projektmanagement, IT-Security, Ingenieur

    EY Deutschland • München, DE
    Are you ready to shape your future with confidence?.Gemeinsam die Welt jeden Tag ein bisschen besser machen.Für diesen Anspruch setzen wir bei EY alles in Bewegung und gehen als Team „al...Mehr anzeigen
    Zuletzt aktualisiert: vor 1 Tag • Gesponsert