SOC Specialist
We are looking for a SOC Specialist to join our cybersecurity team and help protect our infrastructure, applications, endpoints, identities, and cloud environments from evolving cyber threats. You will be responsible for security monitoring, advanced alert investigation, incident response, threat hunting, and continuous improvement of SOC capabilities. You will work closely with Engineering, IT, Cloud, Infrastructure, and Security teams to detect threats, contain incidents, and strengthen our overall security posture. This is a hands-on role suited to someone who enjoys investigating suspicious activity, understanding attacker behaviour, improving detections, and turning security incidents into measurable improvements.
Location: Remote โ Europe
Employment Type: Full-time
Seniority: Mid-Senior / Senior
Department: Cybersecurity / Security Operations
Working Model: 100% Remote
Working Hours: European time zones; participation in on-call/incident response rotation may be required
Key Responsibilities
Security Monitoring & Investigation
- Monitor and investigate security alerts across SIEM, EDR/XDR, cloud, identity, network, email, and application telemetry.
- Perform advanced triage and investigation of suspicious and confirmed security incidents.
- Correlate events across multiple data sources to identify attack patterns and determine scope and impact.
- Investigate endpoint, identity, network, cloud, phishing, malware, and account-compromise incidents.
- Distinguish genuine threats from false positives and continuously improve alert quality.
Incident Response
- Take ownership of security incidents from initial detection through containment, remediation, and closure.
- Coordinate with IT, Infrastructure, Cloud, Engineering, and other stakeholders during active incidents.
- Support containment actions such as endpoint isolation, account suspension, credential rotation, and blocking malicious indicators.
- Maintain clear incident timelines, evidence, root-cause analysis, and remediation recommendations.
- Participate in post-incident reviews and ensure lessons learned are converted into actionable security improvements.
Threat Hunting
- Conduct proactive threat hunting across endpoint, identity, cloud, network, and SaaS environments.
- Develop hypotheses based on threat intelligence, emerging vulnerabilities, and attacker TTPs.
- Use frameworks such as MITRE ATT&CK to identify gaps in detection coverage.
- Research emerging threats and assess their relevance to the organisation.
Detection Engineering & SOC Improvement
- Create, tune, and maintain SIEM correlation rules, detection queries, and alert logic.
- Improve detection coverage while reducing false positives and alert fatigue.
- Develop and maintain SOC playbooks and investigation procedures.
- Identify opportunities for automation and SOAR workflows.
- Contribute to SOC metrics and continuous improvement initiatives, including MTTD, MTTR, detection quality, and escalation accuracy.
Required Experience & Skills
- 5+ years of experience in SOC, Security Operations, Incident Response, Blue Team, or a similar cybersecurity role.
- Strong practical experience investigating security alerts and incidents.
- Hands-on experience with at least one SIEM platform such as:
- Microsoft Sentinel
- Splunk
- Elastic Security
- QRadar
- Google Security Operations
- Wazuh
- Hands-on experience with EDR/XDR technologies such as:
- Microsoft Defender
- CrowdStrike
- SentinelOne
- Cortex XDR
- Strong understanding of:
- Windows and Linux security
- TCP/IP, DNS, HTTP/HTTPS and common network protocols
- Identity and authentication concepts
- Cloud security fundamentals
- Email security and phishing
- Malware and common attack techniques
- Practical knowledge of MITRE ATT&CK and modern attacker TTPs.
- Experience with incident response, containment, remediation, and root-cause analysis.
- Ability to write and understand security queries such as KQL, SPL, or equivalent.
- Strong analytical and investigative mindset.
- Excellent written and spoken English.
- Comfortable working independently in a fully remote environment.
Nice to Have
- Experience with SOAR platforms and security automation.
- Python, PowerShell, Bash, or other scripting experience.
- Threat hunting and detection engineering experience.
- DFIR / digital forensics experience.
- Cloud security experience with Azure, AWS, or GCP.
- Experience with identity platforms such as Microsoft Entra ID / Active Directory.
- Knowledge of Sigma, YARA, or other detection frameworks.
- Experience with vulnerability management and security hardening.
- Experience working in a 24/7 SOC or on-call environment.
- Relevant certifications such as:
- Security+
- SC-200
- BTL1
- GCIH
- GCIA
- GCED
- CISSP