Security Engineer

Giesecke+DevrientOn-siteFull-timeSenior, 5–8 yearsListed 2 weeks ago

Apply now

About this role

Job Title

Security Engineer

Role Summary

The Security Engineer will act as a technical enabler and innovation catalyst across the Cyber Defense Center. This role is responsible for supporting proof-of-concepts (POCs), new security tool integrations, strategic projects, automation initiatives, and advanced SOC capabilities. The role will closely collaborate with SOC Operations, Threat & Vulnerability Management (TVM) to design, test, and operationalize next-generation security solutions, including decoy and deception environments as part of a mature SOC vision. This role bridges strategy, engineering, and operations, ensuring that security capabilities are scalable, integrated, and future-ready.

Key Responsibilities

- Support the implementation and continuous improvement of security controls across cloud environments (Azure, AWS, and/or GCP).

- Assess cloud configurations and workloads for security risks and compliance gaps.

- Collaborate with cloud engineering teams to implement secure-by-design principles.

- Support CNAPP initiatives and remediation programs.

- Act as a technical consultant in the CDC by evaluating, designing, and implementing security solutions aligned with enterprise and SOC maturity goals.

- Support POCs, pilots, and technical evaluations of new security tools, platforms, and capabilities across network, endpoint, cloud, identity, and application security domains.

- Contribute to new integrations between security platforms (SIEM, SOAR, EDR/XDR, TVM, Threat Intelligence, CMDB, ITSM, etc.).

- Translate operational gaps into engineering or automation opportunities .

- Design and set up decoy / deception environments (honeypots, honeytokens, deceptive assets) to enhance threat detection and adversary engagement.

- Contribute to SOAR workflows, scripts, APIs, and integrations (custom or vendor-provided).

- Drive innovation initiatives such as AI/ML-assisted detection, analytics enrichment, and contextual correlation .

- Document architectures, POCs, integration patterns, and operational handover artifacts.

- Assist in the design, implementation, and governance of identity security controls.

- Support authentication, authorization, Single Sign-On (SSO), Multi-Factor Authentication (MFA), and privileged access management initiatives.

- Monitor and analyze identity-related security events and anomalies.

- Contribute to identity governance, role management, and access review processes.

- Develop dashboards, reports, and visualizations to provide actionable security insights.

- Work with SIEM, data lake, and analytics platforms to improve visibility across security domains.

- Support executive and operational reporting requirements.

Required Skills & Experience

- 5–10 years of experience in Security Engineering, SOC, TVM, or Cyber Defense roles .

- Strong hands-on experience in security engineering, SOC technologies, or security architecture .

- Experience with API integrations, scripting, or automation (Python, PowerShell, Bash, or similar).

- Hands-on experience with one or more cloud platforms (Azure, AWS, or GCP).

- Strong understanding of Identity and Access Management concepts and technologies.

- Knowledge of network, endpoint, cloud, and identity security fundamentals .

- Familiarity with deception technologies, honeypots, or attack simulation is a strong plus.

- Experience with Microsoft Security technologies including Microsoft Sentinel, Defender XDR, Entra ID, and Azure Security services.

- Knowledge of cloud-native security controls and container security.

- Familiarity with data engineering concepts and modern analytics platforms.

- Experience in global enterprise or regulated environments is an advantage.

- Exposure to SOC maturity models, Threat Modelling , NIST, MITRE ATT&CK , and modern detection engineering practices.

- Exposure to compliance frameworks is a plus.

Key Competencies

- Ability to work across operations, engineering, and strategy teams.

- Strong analytical mindset with the ability to convert problems into engineering or automation solutions .

- Experience supporting POCs, vendor evaluations, and technical decision-making .

- Excellent documentation and communication skills.

- Continuous learning mindset with a passion for automation and innovation.

- Ability to work effectively in a global and cross-functional environment.

$$ We are an equal opportunity employer! We promote diversity in all its forms and create an inclusive work environment, free from prejudice, discrimination and harassment, in which all employees feel a sense of belonging. We warmly welcome all applications regardless of gender, age, race or ethnic origin, social and cultural background, religion, disability and sexual orientation.

$$ Arvina Mehta $$ [email protected] $$ $$ $$ https://career5.successfactors.eu/career?company=gieseckede&career_job_req_id=27332&career_ns=job_application