IT Security Monitoring Expert - September 2027

KOMMLINk GmbHRemoteContractListed 2 weeks ago

Apply now

About this role

For on of our clients in the energy industry, we are looking for a freelance IT Security Monitoring Expert

Project name: Defending the Castle

Project description: Defending the Castle is the short-term and immediate phase of the clients AI threat resilience response. The purpose is to buy time by increasing detection, response, containment and recovery readiness while a broader Phase 2 plan is prepared for the rest of the Business IT units.

Tasks:

- Conceptual development and structured implementation of the short-term security monitoring strategy for Defending the Castle, focused on detecting AI-augmented threats across hybrid Azure and on-premise environments.

- Translation of frontier-model driven threat scenarios into actionable detection logic, monitoring requirements, telemetry gaps, alerting rules and escalation criteria.

- Provision of technical consultation and recommendations to SOC, Cyber Defense Center, incident response, threat intelligence, cloud, identity, endpoint and platform teams to improve detection coverage at machine-speed threat tempo.

- Definition and validation of monitoring use cases for lateral movement, privilege escalation, identity abuse, cloud control-plane abuse, data staging, exfiltration and persistence across Azure zones and on-premise networks.

- Production of playbooks, SOPs and tuning guidance that allow monitoring teams to detect, triage and escalate AI-assisted attacks with reduced ambiguity and consistent quality.

- Establishment and technical definition of measurable detection coverage, alert quality and response-readiness metrics to support Q1 2027 completion and readiness for Phase 2.

- Creation of immediate visibility into the most likely AI-accelerated attack paths affecting identity, cloud, endpoint, network and privileged access layers.

- Optimization and technical evaluation of telemetry, correlation, enrichment, and alert prioritization for detection efficiency.

- Provision of practical runbooks for SOC and monitoring teams that can be executed under pressure without relying on individual tribal knowledge.

- Conceptual strengthening and technical enhancement of early-warning capability before a broader business IT resilience programme is launched.

- Technical peer review of detection logic across SOC, incident response and platform functions.

- Execution and technical documentation of Purple-team exercises and tabletop scenarios, including simulated alert generation and escalation testing.

- Compilation of an evidence pack containing detection catalog, data-source matrix, runbooks, tuning history and open risk register.

- Preparation of documentation to facilitate operational sign-off from SOC lead, Cyber Defense lead and relevant Azure/on-prem service owners.

- Identification and technical gap analysis of existing processes (too slow, fragmented, undocumented or dependent on informal knowledge) to document optimization potential.

- Transformation of risk evaluations into executable playbooks, technical control frameworks, test protocols, backlog items and management evidence.

- Provision of a structured handover of a Phase 2 backlog and recommendations for the broader Business IT resilience plan after Q1 2027.

- Creation of comprehensive documentation with all results regarding the above-mentioned tasks with subsequent handover to client for review and approval for further usage.

Required skills:

- Minimum 8 years in cyber defense operations, SOC engineering, detection engineering, threat hunting or security monitoring.

- Strong expertise in SIEM, XDR, EDR, Microsoft Sentinel or equivalent platforms, KQL/SPL-style query languages and cloud/security telemetry.

- Good understanding of Azure security monitoring, Entra ID, hybrid identity, endpoint telemetry, network logs, MITRE ATT&CK and attack-chain analysis.

- Experience creating operational runbooks, alert tuning processes and SOC quality metrics.

- Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP or equivalent are beneficial

Start: ASAP
Duration: till end of March 2027
Capacity: 40h/week
Location: Remote