> Markdown version of [/jobs/ext/2687179-security-engineer-soc](https://www.wearedevelopers.com/jobs/ext/2687179-security-engineer-soc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (SOC) - **Company:** APT GmbH - **Location:** Berlin, Germany - **Experience:** Expert - **Salary:** €80,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Engineering, Cyber Security, Continuous Integration, Identity and Access Management, Python (Programming Language), Log Analysis, Open Web Application Security, Parsing, Public Key Infrastructure, Windows PowerShell, Kusto Query Language, Sherwood Applied Business Security Architecture, Security Information and Event Management, Management of Software Versions, Google Cloud, Large Language Models, Prompt Engineering, Mitre Att&ck, Togaf - **Published:** September 3, 2026 - **Apply:** https://www.adzuna.de/details/5865222770 ## About the Role * Souveräner Umgang mit KI-Werkzeugen im Beratungsalltag inkl. kritischer Bewertung der Ergebnisse * Ausgeprägtes Bewusstsein für Vertraulichkeit beim KI-Einsatz: Du weißt, welche Daten in welches System dürfen, und kennst die Risiken (Datenabfluss, Modelltraining, Prompt Injection) * Bereitschaft, Prozesse und Produkte kontinuierlich KI-basiert weiterzuentwickeln * Mindestens 5 Jahre Erfahrung in IT-/Cyber-Security, davon mehrere Jahre in Architektur- oder Beratungsrollen * Breites Technologieverständnis über Netzwerk, Endpoint, Identity, Applikation und Cloud * Erfahrung mit Zero-Trust- und Segmentierungskonzepten sowie IAM/PAM (Entra ID, Active Directory) * Sicherer Umgang mit ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, SABSA/TOGAF * Kenntnisse in Kryptografie, PKI und sicherem Applikationsdesign * Verhandlungssichere Deutsch- und Englischkenntnisse Von großem Vorteil: * Cloud-Architekten-Know-how: Design, Absicherung und Betrieb von Cloud- und Hybrid-Umgebungen (Azure, AWS, GCP), Cloud-native Security-Dienste, Infrastructure-as-Code * Erfahrung mit Prompt Engineering, KI-Agenten oder LLM-Integration in Workflows * Kenntnisse in KI-Governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM) * Erfahrung in regulierten Umgebungen (KRITIS, Finanzsektor, Industrie/OT) Zertifizierungen (nice to have): OffSec (Hands-on & Offensive/Defensive Integration) * OSDA (Defense Analyst - SOC-200) * OSCP (PEN-200) * SANS / GIAC (Architektur & Tactical Detection) * GCDA (SANS SEC555) * GDSA (SANS SEC530) * GCIH (SANS SEC504) ## Description * Aufbau, Betrieb und Weiterentwicklung von SOC-Plattformen (SIEM, SOAR, EDR/XDR) * Onboarding neuer Logquellen inklusive Parsing, Normalisierung und Sicherstellung der Datenqualität * Entwicklung und Optimierung von Detection-Regeln und Use Cases (Sigma, KQL, SPL) auf Basis von MITRE ATT&CK * Automatisierung von Analyse- und Response-Prozessen durch Playbooks und Skripting (Python, PowerShell) * Aufbau von Detection-as-Code-Pipelines inkl. Versionierung, Testing und CI/CD * Integration und Operationalisierung von Threat Intelligence * Enge Zusammenarbeit mit Analyst:innen und Incident Respondern zur Reduktion von False Positives und Verbesserung der Detection-Qualität * Technische Unterstützung bei Sicherheitsvorfällen * Erstellung von Runbooks, Use-Case-Dokumentationen und technischen Konzepten * Einsatz KI-gestützter Werkzeuge für Log-Analyse, Regel- und Playbook-Entwürfe sowie Dokumentation - inklusive fachlicher Validierung und Freigabe der Ergebnisse ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Building a Compiler with C#](https://www.wearedevelopers.com/videos/116-building-a-compiler-with-c) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Scrape, Train, Predict: The Lifecycle of Data for AI Applications](https://www.wearedevelopers.com/videos/1652-scrape-train-predict-the-lifecycle-of-data-for-ai-applications) ## Related Articles - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)