Engineer - Security Operations and Incident Response

EarcaíochtJobgetherBrussels (Firmensitz, recherchiert)Job.bofoilsithe 09/09/2026
Riachtanach:PythonAzureGoogle CloudCloudAISecurityRemoteHybrid

Accountabilities: Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.

Develop, author, and continuously refine incident response playbooks and operational guidelines to ensure effective responses to evolving threats.

Develop and maintain threat models, incorporating penetration testing findings into detection strategies and security improvements.

Design, implement, and optimize sophisticated detection rules and automated remediation workflows to identify and respond to adversarial behavior.

Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps and proactively mitigate emerging cybersecurity risks.

Maintain comprehensive documentation covering detection strategies, active investigations, incident timelines, and response activities.

Partner with SIEM teams to continuously tune detection rules, improving detection fidelity while minimizing false positives and alert fatigue.

Review and optimize threat intelligence capabilities, including brand protection and dark web monitoring systems.

Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash to support security investigations and operational efficiency.

Implement and maintain automation and orchestration capabilities through SOAR tools and related technologies.

Support incident response leadership as a backup resource for incident response activities and operational priorities.

Contribute to the continuous improvement of security operations processes, technologies, and overall incident response maturity.

Requirements:

Bachelor's degree and at least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.

In-depth knowledge of SIEM and SOAR platforms, with experience in technologies such as Microsoft Sentinel, Palo Alto Cortex XSIAM, and Cortex XSOAR.

Strong understanding of incident response processes within hybrid cloud environments, including GCP and Azure.

Experience serving as an incident commander during security incidents and leading coordinated response efforts.

Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools, processes, and detection capabilities.

Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.

Understanding of cybersecurity frameworks and regulatory requirements, including MITRE ATT&CK, NIST, and ISO.

Experience with threat intelligence, detection engineering, security automation, and incident response processes.

Strong analytical and problem-solving skills, with the ability to investigate complex security events and develop practical solutions.

Ability to prioritize effectively, manage multiple concurrent priorities, and work independently as well as collaboratively.

Excellent written and verbal communication skills, including the ability to translate sophisticated technical security concepts into clear, concise business-focused explanations.

Benefits:

Remote or hybrid work options.

Opportunity to work on the ongoing transformation of a global Security Operations and Incident Response program.

Exposure to advanced cybersecurity technologies, including SIEM, SOAR, threat intelligence, security automation, and cloud security platforms.

Opportunity to work with modern security frameworks and methodologies such as MITRE ATT&CK, NIST, and ISO.

High-impact role focused on strengthening enterprise resilience and protecting against evolving cybersecurity threats.

Opportunity to contribute to continuous process improvement and the advancement of security operations capabilities.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1