Job Closed
This listing is no longer active.
The place where creative problem-solvers that care for people, solutions, and their impact thrive
Security Operations Center Architect
Location
Romania
Posted
132 days ago
Salary
0
Seniority
Senior
Job Description
Security Operations Center Architect
accesa.eu
• Architect the Modern SOC → Lead the end-to-end design of a cloud-native SOC, defining the strategy, Azure technical architecture, and operational model aligned with Zero Trust and business needs. • Translate Risk into Detection → Convert abstract security strategies and business risks into actionable detection logic by designing and maintaining advanced analytics rules using KQL in Microsoft Sentinel. • Optimize Security at Scale → Design cost-efficient ingestion and retention strategies, including Log Tiering (Analytics, Basic, Archive), balancing visibility, performance, and Azure ingestion costs. • Engineer SIEM & XDR Integrations → Architect seamless integrations between Microsoft Sentinel and the Microsoft Defender XDR suite (MDE, MDI, MDA, MDO), enabling bi-directional synchronization and enriched incidents. • Automate Response & Operations → Design and implement advanced SOAR playbooks using Azure Logic Apps or Power Automate to automate incident enrichment, response, and containment actions. • Enable Operational Excellence → Define SOC workflows, incident response processes, health monitoring, and KPI visualization (MTTD, MTTR, FPR), while mentoring Tier 3 analysts and ensuring sustainable operations.
Job Requirements
- Deep hands-on experience with Microsoft Sentinel, Log Analytics Workspaces, and the Defender XDR ecosystem.
- Advanced proficiency in Kusto Query Language for analytics rules, hunting queries, and performance optimization.
- Strong experience designing automation using Azure Logic Apps, Power Automate, and SOAR concepts.
- Proven experience designing SOC architectures, Log Analytics Workspace topologies, and MSSP models using Azure Lighthouse.
- Solid understanding of NIDS/NIPS, Windows/Linux security, and hybrid log ingestion (CEF, AMA, CCF).
- 5+ years in Cyber Security, SOC, Incident Response, or Security Engineering, with the ability to bridge technical execution and executive strategy.
- Security certifications such as Microsoft SC-100, SC-200, or industry equivalents such as CISSP or CISM are nice to have.
Benefits
- Our wellbeing program includes medical benefits, gym support, and personalised fitness options for an active lifestyle, complemented by team events and the Healthy Habits Club.
- Having a one-size-fits-one approach gives us the flexibility to define the work-life dynamic that works for us.
- We believe that to maintain our overall health, we need to invest in our mental wellbeing just as much as we do in our physical health, social connections or in achieving work-life balance.
- As a growing community in a hybrid environment, we want to ensure we remain connected not just by the great work we do every day but through our passions and interests.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Act as the primary technical escalation point for complex operational issues, ensuring quick and effective resolutions. • Maintain and optimize critical systems, including SIEM platforms (e.g., Splunk, ELK, SumoLogic, Sentinel), Anti-Virus tools (Trend Micro Deep Security Manager, Microsoft Defender, Crowdstrike) and vulnerability management tools (e.g., Nessus, Qualys, Burp). • Monitor and improve the team’s use of automation and monitoring tools to drive operational efficiency. • Analyze and resolve system performance issues, ensuring compliance with security and operational standards. • Participate in incident response and post-mortem analysis to identify root causes and prevent recurrence. • Mentor and support the professional growth of engineers through training, feedback, and career development planning. • Assist with hiring, onboarding, and retention to ensure team stability and growth. • Oversee day-to-day delivery of security services, ensuring operational consistency and high-quality outcomes. • Track and optimize key metrics such as incident response times, operational efficiency, and compliance posture. • Develop and refine processes for incident response, vulnerability remediation, and compliance reporting. • Work with cross-functional teams, including consulting teams, SREs, and professional services teams, to improve service delivery.
• Lead and coordinate responses to security incidents, including ransomware, host compromise, credential and account compromise, phishing, insider threats, third-party risks, and data spillage while collaborating closely with information security leadership, business stakeholders, and the rest of the incident response team • Produce clear, accurate incident documentation and post‑incident analysis focused on root cause and measurable improvement • Participate in incident response tabletop exercises to identify gaps, enhance skills, and engage stakeholders; review technical reports from vulnerability and penetration testing assessments to identify potential exposure to future incidents • Improve Security Operations practices by contributing to the development, refinement, and maintenance of SOC procedures, playbooks, policies, and guidelines • Assess the effectiveness of security controls and technical risks across hosting environments, and communicate findings clearly to both technical and non-technical stakeholders • Own and act as a subject matter expert for one or more core security tools or platforms, ensuring data quality, reliable operation, and effective use.
• Monitor and analyze log data, network traffic, and/or alerts generated by a variety of security technologies in real-time. • Respond, triage, and escalate security incidents using a SIEM platform following documented procedures. • Support the execution of vulnerability scans and assist in analyzing results for remediation recommendations. • Draft security incident reports detailing the threat, its characteristics, and required remediation activities for review by a senior analyst. • Research new threats and ensure appropriate detection capabilities are in place. • Review security incidents and other deliverables for adherence to established procedures and provide documentation updates as necessary. • Contribute to the quality and timeliness of the security incident detection and classification service. • Ensure standards and procedures are adhered to within defined SLA’s. • Articulate security issues to customers, both verbally and written. • Referring difficult or complex issues to more experienced staff. • Developing an understanding of current vulnerabilities, attacks, and countermeasures. • Identify opportunities for process improvement and suggest them to stakeholders. • Manage and track customer issues and requests within a ticketing system. • Work within a 24x7x365 team to further support the timely delivery of monitoring services. • This position may be assigned to a rotating shift schedule. • Support other teams as needed.
SOC Analyst Intern
ATPCOATPCO is committed to providing the best flight shopping experiences through reliable pricing data and innovative retail technology. Positioning itself as "the foundation of modern
• Monitor security alerts and events using SIEM and other monitoring tools. • Analyze and respond to security incidents, including malware infections, phishing attempts, and unauthorized access. • Triage and prioritize alerts based on severity and potential impact. • Conduct initial investigations and document findings in incident tracking systems. • Collaborate with internal teams to contain and remediate security threats. • Perform root cause analysis and recommend improvements to prevent recurrence. • Create and maintain standard operating procedures (SOPs) and incident response playbooks. • Assist in threat intelligence gathering and correlation with internal events. • Participate in security audits, vulnerability assessments, and compliance efforts. • Stay up-to-date with the latest cybersecurity trends, vulnerabilities, and threat actor tactics.



