2 months ago
Athens, GreeceSenior
Responsibilities
- Onboard customer log sources into Microsoft Sentinel and Elastic Cloud using native connectors or managed log forwarders.
- Design, deploy, and maintain customer-environment log-forwarding infrastructure, including load-balanced forwarder clusters.
- Build and maintain parsing, normalization, and enrichment logic for reliable SIEM detection data.
- Configure and integrate Microsoft Defender for Endpoint, Microsoft Defender XDR, Cortex XDR, SentinelOne, Azure, and AWS monitoring into the MSS delivery stack.
- Support detection engineering through platform-side rule deployment and testing across SIEM and EDR/XDR platforms.
- Build AI-enabled solutions such as analyst workflow assistance, automated triage, LLM-backed enrichment, and reporting.
- Contribute to the NVISO Core platform, including Azure Functions, Durable Task Scheduler, Application Insights, Log Analytics, and Bicep-based infrastructure.
- Contribute to self-service onboarding and broader MSS service improvements.
- Define reusable engineering patterns and building blocks instead of only customer-specific point solutions.
- Run technical workshops, capture requirements, and translate them into implementation plans and roadmaps.
- Act as a technical reference for junior colleagues through coaching and knowledge sharing.
Requirements
- Hands-on experience with a major SIEM platform such as Microsoft Sentinel, Elastic, Splunk, or a similar platform, including log onboarding, parsing or normalization, and rule deployment.
- Solid understanding of SOC operations, incident response workflows, detection engineering, SOC engineering, and SOC analysis.
- Working knowledge of log-forwarding technologies and centralized collector patterns such as Logstash, Elastic Agent, syslog collectors, and cloud-native connectors.
- Strong foundation in Python or other scripting and automation languages, with comfort using APIs.
- Practical experience with an EDR/XDR ecosystem such as Microsoft Defender for Endpoint, Defender XDR, Cortex XDR, or SentinelOne, or willingness to specialize in one.
- Familiarity with Azure and/or AWS security telemetry, including audit logs, activity data, identity signals, and cloud-native detection tooling.
- Ability to develop scalable engineering patterns, reusable building blocks, and implementation roadmaps.
- Exposure to SOAR platforms such as XSOAR, case management workflows, and playbook development is preferred.
- Experience with Infrastructure-as-Code using Bicep or Terraform and Azure application components such as Azure Functions, Log Analytics, and Application Insights is preferred.
- Experience with AI/LLM solutions, GenAI-assisted automation, prompt engineering, or LLM API integration is a strong plus.
- Familiarity with Azure AI Foundry or a comparable AI platform is preferred.
- Citizenship in one of the 32 NATO member states or Austrian citizenship is required.
- Ability to work independently, prioritize work, communicate effectively, document and present work, and combine strategic thinking with hands-on implementation.
- Excellent written and verbal English communication skills.
Benefits
- €10,000 training budget and 10 training days every two years.
- Flexible working model, home-office options, and opportunities to work abroad.
- Statutory leave plus five additional NVISO leave days.
- Additional monthly and annual benefits.
- Entrepreneurial and agile environment supporting internal innovation and service improvements.
- Access to experienced cybersecurity professionals, SANS instructors, conferences, and deep technical security certification opportunities.
- Personal coaching and career-development support from a team coach.
About NVISO
NVISO is a Brussels-based cybersecurity services firm founded in 2013. It delivers penetration testing, digital forensics and incident response, security monitoring and threat hunting, governance/risk/compliance, adversary emulation, and ICS security to private companies and government agencies. The company operates as a privately held partnership and serves clients across Europe, including teams in Belgium and Germany.
