NVISO

SOC Engineer

NVISO
Apply
2 months ago
Athens, GreeceSenior

Responsibilities

  • Onboard customer log sources into Microsoft Sentinel and Elastic Cloud using native connectors or managed log forwarders.
  • Design, deploy, and maintain customer-environment log-forwarding infrastructure, including load-balanced forwarder clusters.
  • Build and maintain parsing, normalization, and enrichment logic for reliable SIEM detection data.
  • Configure and integrate Microsoft Defender for Endpoint, Microsoft Defender XDR, Cortex XDR, SentinelOne, Azure, and AWS monitoring into the MSS delivery stack.
  • Support detection engineering through platform-side rule deployment and testing across SIEM and EDR/XDR platforms.
  • Build AI-enabled solutions such as analyst workflow assistance, automated triage, LLM-backed enrichment, and reporting.
  • Contribute to the NVISO Core platform, including Azure Functions, Durable Task Scheduler, Application Insights, Log Analytics, and Bicep-based infrastructure.
  • Contribute to self-service onboarding and broader MSS service improvements.
  • Define reusable engineering patterns and building blocks instead of only customer-specific point solutions.
  • Run technical workshops, capture requirements, and translate them into implementation plans and roadmaps.
  • Act as a technical reference for junior colleagues through coaching and knowledge sharing.

Requirements

  • Hands-on experience with a major SIEM platform such as Microsoft Sentinel, Elastic, Splunk, or a similar platform, including log onboarding, parsing or normalization, and rule deployment.
  • Solid understanding of SOC operations, incident response workflows, detection engineering, SOC engineering, and SOC analysis.
  • Working knowledge of log-forwarding technologies and centralized collector patterns such as Logstash, Elastic Agent, syslog collectors, and cloud-native connectors.
  • Strong foundation in Python or other scripting and automation languages, with comfort using APIs.
  • Practical experience with an EDR/XDR ecosystem such as Microsoft Defender for Endpoint, Defender XDR, Cortex XDR, or SentinelOne, or willingness to specialize in one.
  • Familiarity with Azure and/or AWS security telemetry, including audit logs, activity data, identity signals, and cloud-native detection tooling.
  • Ability to develop scalable engineering patterns, reusable building blocks, and implementation roadmaps.
  • Exposure to SOAR platforms such as XSOAR, case management workflows, and playbook development is preferred.
  • Experience with Infrastructure-as-Code using Bicep or Terraform and Azure application components such as Azure Functions, Log Analytics, and Application Insights is preferred.
  • Experience with AI/LLM solutions, GenAI-assisted automation, prompt engineering, or LLM API integration is a strong plus.
  • Familiarity with Azure AI Foundry or a comparable AI platform is preferred.
  • Citizenship in one of the 32 NATO member states or Austrian citizenship is required.
  • Ability to work independently, prioritize work, communicate effectively, document and present work, and combine strategic thinking with hands-on implementation.
  • Excellent written and verbal English communication skills.

Benefits

  • €10,000 training budget and 10 training days every two years.
  • Flexible working model, home-office options, and opportunities to work abroad.
  • Statutory leave plus five additional NVISO leave days.
  • Additional monthly and annual benefits.
  • Entrepreneurial and agile environment supporting internal innovation and service improvements.
  • Access to experienced cybersecurity professionals, SANS instructors, conferences, and deep technical security certification opportunities.
  • Personal coaching and career-development support from a team coach.

Tech Stack

Categories

NVISO

About NVISO

201-500 employees

NVISO is a Brussels-based cybersecurity services firm founded in 2013. It delivers penetration testing, digital forensics and incident response, security monitoring and threat hunting, governance/risk/compliance, adversary emulation, and ICS security to private companies and government agencies. The company operates as a privately held partnership and serves clients across Europe, including teams in Belgium and Germany.

Contact me