Security Monitoring Expert (m/f/d) ID27155-2

Security Monitoring Expert (m/f/d) ID27155-2

Düsseldorf Vollzeit Kein Homeoffice möglich
C

Security Monitoring Expert (m/f/d) ID27155-2


Duration: 21.09.2026 – 31.03.2027

Volumen: 40h/week

Location: remote


Please submit your profiles in English!


Project description: “Defending the Castle” is the short-term and immediate phase of our customers AI threat resilience response. The purpose is to buy time by increasing detection, response, containment and recovery readiness while a broader Phase 2 plan is prepared for the rest of the Business IT units.


Task description:

- Conceptual development and structured implementation of the short-term security monitoring strategy for “Defending the Castle”, focused on detecting AI-augmented threats across hybrid Azure and on-premise environments.

- Translation of frontier-model driven threat scenarios into actionable detection logic, monitoring requirements, telemetry gaps, alerting rules and escalation criteria.

- Provision of technical consultation and recommendations to SOC, Cyber Defense Center, incident response, threat intelligence, cloud, identity, endpoint and platform teams to improve detection coverage at machine-speed threat tempo.

- Definition and validation of monitoring use cases for lateral movement, privilege escalation, identity abuse, cloud control-plane abuse, data staging, exfiltration and persistence across Azure zones and on-premise networks.

- Production of playbooks, SOPs and tuning guidance that allow monitoring teams to detect, triage and escalate AI-assisted attacks with reduced ambiguity and consistent quality.

- Establishment and technical definition of measurable detection coverage, alert quality and response-readiness metrics to support Q1 2027 completion and readiness for Phase 2.

- Creation of immediate visibility into the most likely AI-accelerated attack paths affecting identity, cloud, endpoint, network and privileged access layers.

- Optimization and technical evaluation of telemetry, correlation, enrichment, and alert prioritization for detection efficiency.

- Provision of practical runbooks for SOC and monitoring teams that can be executed under pressure without relying on individual tribal knowledge.

- Conceptual strengthening and technical enhancement of early-warning capability before a broader business IT resilience programme is launched.

Quality

- Technical peer review of detection logic across SOC, incident response and platform functions.

- Execution and technical documentation of Purple-team exercises and tabletop scenarios, including simulated alert generation and escalation testing.

- Compilation of an evidence pack containing detection catalog, data-source matrix, runbooks, tuning history and open risk register.

- Preparation of documentation to facilitate operational sign-off from SOC lead, Cyber Defense lead and relevant Azure/on-prem service owners.

- Identification and technical gap analysis of existing processes (too slow, fragmented, undocumented or dependent on informal knowledge) to document optimization potential.

- Transformation of risk evaluations into executable playbooks, technical control frameworks, test protocols, backlog items and management evidence.

- Provision of a structured handover of a Phase 2 backlog and recommendations for the broader Business IT resilience plan after Q1 2027.

- Creation of comprehensive documentation with all results regarding the above-mentioned tasks with subsequent handover to Uniper for review and approval for further usage.


Skills:

Please submit profiles in english for the Security Monitoring Expert.

• Minimum 8 years in cyber defense operations, SOC engineering, detection engineering, threat hunting or security monitoring.

• Strong expertise in SIEM, XDR, EDR, Microsoft Sentinel or equivalent platforms, KQL/SPL-style query languages and cloud/security telemetry.

• Good understanding of Azure security monitoring, Entra ID, hybrid identity, endpoint telemetry, network logs, MITRE ATT&CK and attack-chain analysis.

• Experience creating operational runbooks, alert tuning processes and SOC quality metrics.

• Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP or equivalent are beneficial.



Security Monitoring Expert (m/f/d) ID27155-2 Arbeitgeber: C4 Energy & Co. KG

Als Junior Tester (m/w/d) im Bereich SAP S/4HANA Finance R2R bieten wir Ihnen die Möglichkeit, in einem dynamischen und unterstützenden Team zu arbeiten, das Wert auf kontinuierliche Weiterbildung und persönliche Entwicklung legt. Unsere remote Arbeitskultur ermöglicht es Ihnen, flexibel zu arbeiten und gleichzeitig an spannenden Projekten teilzuhaben, die Ihre Fähigkeiten erweitern und Ihre Karriere vorantreiben. Profitieren Sie von einer offenen Kommunikation und einem Umfeld, das Innovation und Zusammenarbeit fördert.

C

Kontaktdaten:

C4 Energy & Co. KG Recruiting-Team