Job
- Level
- Lead
- Job Feld
- IT, Security
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
- Ort
- München
- Arbeitsmodell
- Hybrid, Onsite
Job Zusammenfassung
In dieser Position erstellst du hochpräzise Erkennungsregeln, analysierst Cyber-Bedrohungen und entwickelst automatisierte Reaktionsabläufe, um die Sicherheitslage zu optimieren und den SOC zu unterstützen.
Job Technologien
Deine Rolle im Team
- Lead Detection Strategy: Define the long-term vision for detection engineering, aligning technical roadmaps with organizational risk profiles while standardizing the development lifecycle.
- Engine & Rule Lifecycle Management: Architect, develop, maintain, and optimize high-fidelity detection rules for the SOC while expanding framework coverage against MITRE ATT&CK® and Sigma standards.
- Threat Intelligence Translation: Analyze Cyber Threat Intelligence (CTI) and translate complex TTPs into proactive, resilient detection logic.
- Automation & Orchestration: Drive 'Detection-as-Code' initiatives and engineer automated response playbooks to streamline incident response and minimize manual intervention.
- Technical Mentorship & Escalation: Act as the primary escalation point for complex technical issues, mentoring junior detection engineers and SOC analysts.
- Cross-Functional Collaboration: Partner closely with Incident Response and SOC teams to ensure deployment of context-rich detections that enable rapid threat containment.
Unsere Erwartungen an dich
Ausbildung
- Degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
Qualifikationen
- Deep technical expertise in Windows and Linux operating systems, including OS internals, system logging, and telemetry analysis.
- Practical background in Red Teaming, Penetration Testing, or an offensive mindset to anticipate attacker methodologies.
- Advanced expertise with the MITRE ATT&CK® framework and Detection-as-Code concepts.
- Strong communication skills with an empathetic, collaborative approach to leading cross-functional teams and technical initiatives.
Erfahrung
- Proven track record in developing use cases and detection logic within a Security Operations Center (SOC) environment, including leadership or mentorship experience.
- Strong proficiency in Python and hands-on experience with automation frameworks to streamline operations.
Unser Angebot
- Fair Compensation & Extras: Attractive remuneration and individual additional benefits, such as company pension schemes, mobility offers (e.g., bike leasing), or corporate discounts with partner companies in accordance with our current guidelines.
- Time for You (and Your Loved Ones): 30 days of annual leave based on our collective agreement (35-hour week); work-life balance through flexible working hours (flextime), mobile working, part-time options, job sharing, and sabbatical opportunities.
- Growth Made Easy: Excellent professional development opportunities and international, group-wide career perspectives.
- Feel Good at Work: On-site company doctor; comprehensive health programs (sports courses, preventive care, etc.), canteen and cafeteria, and local childcare facilities at selected locations.
- Diversity Connects: Work in a diverse environment with more than 140 nationalities, where exchange, mutual support, and inclusion are part of our DNA.
Benefits
Work-Life-Integration
Gesundheit, Fitness & Fun
Essen & Trinken
Mehr Netto
Themen mit denen du dich im Job beschäftigst
Job Standorte
Das ist dein Arbeitgeber
Airbus Deutschland GmbH
Airbus ist ein renommiertes Luft- und Raumfahrtunternehmen mit Dienstleistungen, die weltweit Maßstäbe setzen.
Description
- Sprachen
- Englisch
- Unternehmenstyp
- Etablierte Firma
- Arbeitsmodell
- Full Remote, Hybrid, Onsite
- Branche
- Fahrzeugbau, Zulieferer, Industrie, Produktion
Arbeitgeber-Reviews
von devworkplaces.com
Gesamt
(1 Bewertung)3.3
Career Growth
3.2Engineering
2.8Workingconditions
4.0Culture
3.5