2 months ago
Athens, GreeceSenior
Responsibilities
- Onboard customer log sources into Microsoft Sentinel and Elastic Cloud using native connectors or managed log forwarders.
- Design, deploy, and maintain customer-environment log forwarding infrastructure, including load-balanced forwarder clusters.
- Build and maintain parsing, normalization, and enrichment logic for reliable SIEM detection data.
- Configure and integrate EDR/XDR platforms and Azure/AWS cloud monitoring into the managed security services stack.
- Support detection engineering with platform-side rule deployment and testing across SIEM and EDR/XDR ecosystems.
- Build AI- and LLM-enabled solutions for analyst workflows, automated triage, enrichment, and reporting.
- Contribute to the Azure-based core platform and self-service onboarding capabilities.
- Define reusable engineering patterns and building blocks instead of isolated customer-specific solutions.
- Lead technical workshops, translate requirements into implementation plans, and act as a technical reference for junior colleagues.
Requirements
- Hands-on experience with at least one major SIEM platform, including log onboarding, parsing or normalization, and rule deployment.
- Understanding of SOC operations, incident response workflows, detection engineering, SOC engineering, and SOC analysis.
- Working knowledge of log forwarding and centralized collector technologies such as Logstash, Elastic Agent, syslog collectors, and cloud-native connectors.
- Strong foundation in Python or other scripting and automation languages, with comfort using APIs.
- Practical experience with at least one EDR/XDR ecosystem such as Microsoft Defender for Endpoint, Microsoft Defender XDR, Cortex XDR, or SentinelOne, or a desire to specialize in one.
- Familiarity with Azure and/or AWS security telemetry, including audit logs, activity data, identity signals, and cloud-native detection tooling.
- Ability to design scalable engineering patterns, reusable building blocks, and implementation roadmaps.
- Exposure to SOAR platforms such as XSOAR, case management workflows, and playbook development is preferred.
- Experience with Infrastructure-as-Code using Bicep or Terraform and Azure application components is preferred.
- Experience with AI/LLM solutions, GenAI-assisted automation, prompt engineering, or LLM APIs is a strong plus.
- Familiarity with Azure AI Foundry or comparable AI platforms is preferred.
- Strong communication, documentation, presentation, prioritization, collaboration, and independent-work skills.
- Excellent written and spoken English.
- Citizenship in one of the 32 NATO member states or Austrian citizenship is required.
Benefits
- Training budget of €10,000 and 10 training days every two years.
- Flexible working model, home-office possibilities, and options to work abroad.
- Statutory leave plus five additional NVISO leave days.
- Additional monthly and annual benefits.
- Entrepreneurial and agile environment with opportunities to drive internal innovation and improve service offerings.
- Access to learning from experienced European cybersecurity professionals and opportunities to pursue technical certifications.
- Personal coaching and career-development support.
- The posting states that AI tools may be used only to a limited extent for application documents, such as proofreading or wording improvements, and that fully AI-generated documents are not permitted.
About NVISO
NVISO is a Brussels-based cybersecurity services firm founded in 2013. It delivers penetration testing, digital forensics and incident response, security monitoring and threat hunting, governance/risk/compliance, adversary emulation, and ICS security to private companies and government agencies. The company operates as a privately held partnership and serves clients across Europe, including teams in Belgium and Germany.
