NVISO

SOC Engineer

NVISO
Apply
2 months ago
Athens, GreeceSenior

Responsibilities

  • Onboard customer log sources into Microsoft Sentinel and Elastic Cloud using native connectors or managed log forwarders.
  • Design, deploy, and maintain customer-environment log forwarding infrastructure, including load-balanced forwarder clusters.
  • Build and maintain parsing, normalization, and enrichment logic for reliable SIEM detection data.
  • Configure and integrate EDR/XDR platforms and Azure/AWS cloud monitoring into the managed security services stack.
  • Support detection engineering with platform-side rule deployment and testing across SIEM and EDR/XDR ecosystems.
  • Build AI- and LLM-enabled solutions for analyst workflows, automated triage, enrichment, and reporting.
  • Contribute to the Azure-based core platform and self-service onboarding capabilities.
  • Define reusable engineering patterns and building blocks instead of isolated customer-specific solutions.
  • Lead technical workshops, translate requirements into implementation plans, and act as a technical reference for junior colleagues.

Requirements

  • Hands-on experience with at least one major SIEM platform, including log onboarding, parsing or normalization, and rule deployment.
  • Understanding of SOC operations, incident response workflows, detection engineering, SOC engineering, and SOC analysis.
  • Working knowledge of log forwarding and centralized collector technologies such as Logstash, Elastic Agent, syslog collectors, and cloud-native connectors.
  • Strong foundation in Python or other scripting and automation languages, with comfort using APIs.
  • Practical experience with at least one EDR/XDR ecosystem such as Microsoft Defender for Endpoint, Microsoft Defender XDR, Cortex XDR, or SentinelOne, or a desire to specialize in one.
  • Familiarity with Azure and/or AWS security telemetry, including audit logs, activity data, identity signals, and cloud-native detection tooling.
  • Ability to design scalable engineering patterns, reusable building blocks, and implementation roadmaps.
  • Exposure to SOAR platforms such as XSOAR, case management workflows, and playbook development is preferred.
  • Experience with Infrastructure-as-Code using Bicep or Terraform and Azure application components is preferred.
  • Experience with AI/LLM solutions, GenAI-assisted automation, prompt engineering, or LLM APIs is a strong plus.
  • Familiarity with Azure AI Foundry or comparable AI platforms is preferred.
  • Strong communication, documentation, presentation, prioritization, collaboration, and independent-work skills.
  • Excellent written and spoken English.
  • Citizenship in one of the 32 NATO member states or Austrian citizenship is required.

Benefits

  • Training budget of €10,000 and 10 training days every two years.
  • Flexible working model, home-office possibilities, and options to work abroad.
  • Statutory leave plus five additional NVISO leave days.
  • Additional monthly and annual benefits.
  • Entrepreneurial and agile environment with opportunities to drive internal innovation and improve service offerings.
  • Access to learning from experienced European cybersecurity professionals and opportunities to pursue technical certifications.
  • Personal coaching and career-development support.
  • The posting states that AI tools may be used only to a limited extent for application documents, such as proofreading or wording improvements, and that fully AI-generated documents are not permitted.

Tech Stack

Categories

NVISO

About NVISO

201-500 employees

NVISO is a Brussels-based cybersecurity services firm founded in 2013. It delivers penetration testing, digital forensics and incident response, security monitoring and threat hunting, governance/risk/compliance, adversary emulation, and ICS security to private companies and government agencies. The company operates as a privately held partnership and serves clients across Europe, including teams in Belgium and Germany.

Contact me