About this role
Founded in 1999 in Vienna, the Qualysoft Group is a manufacturer-independent IT consulting and services company, which successfully provides support for its international customers with the aim of boosting their competitiveness and economic efficiency through innovative IT solutions.
Its focus is on financial services providers, telecommunications companies, the automotive industry and energy service providers. Over 400 employees in 6 subsidiaries work together to ensure state of the art solutions for our clients.
We are looking for new colleagues in Qualysoft teams for diverse projects providing continuous learning opportunities. Our common goal is to provide honesty, development and a stable background while getting to know the latest technologies. We are waiting for your application for the position below!
Responsibilities:
- Monitor and respond to security alerts on a 24/7 basis , including participation in an on-call rotation.
- Perform initial alert triage and validation using logs, telemetry, and contextual information ( Tier 1 analysis ).
- Work directly with internal stakeholders and system owners to validate and investigate security events ( Tier 2 analysis ).
- Escalate confirmed or high-risk incidents to Tier 3 or Incident Response teams, providing detailed investigation findings.
- Develop, tune, and continuously improve detection rules, alert logic, and correlation use cases based on real-world threats and the MITRE ATT&CK Framework .
- Support and co-lead security investigations, including root-cause analysis, identification of lateral movement, and assessment of potential data exposure.
- Proactively identify emerging threats through threat hunting and purple teaming exercises .
- Contribute to the development and continuous improvement of SOC playbooks, investigation runbooks, and incident response procedures .
- Support the customization of security response strategies for the specific technical and organizational characteristics of SAP Cloud Infrastructure .
- Create and maintain security dashboards, metrics, and KPIs to measure SOC effectiveness and monitor threat landscape trends.
- Participate in lessons-learned reviews and provide recommendations to improve security detection and response processes.
Requirements:
- Bachelor's degree in Computer Science, Information Security , or a related technical field, or equivalent practical experience.
- 2–4 years of experience in a Security Operations Center (SOC) or cybersecurity operations role, preferably in cloud-based or hybrid environments.
- Solid understanding of cloud security principles and experience with Microsoft Azure, AWS, or GCP.
- Hands-on experience securing and monitoring workloads in public cloud environments.
- Strong knowledge of security logging, monitoring, and SIEM platforms , such as Splunk, ElasticSearch, OpenSearch, or Datadog.
- Experience with Threat Intelligence Platforms and security monitoring tools.
- Strong understanding of networking protocols, Linux systems, Kubernetes, container technologies, and common security controls.
- Familiarity with Docker and Kubernetes .
- Knowledge of the MITRE ATT&CK Framework , NIST incident handling lifecycle, and basic malware behavior.
- Hands-on experience with security alert triage, basic forensic analysis, and incident response support .
- Experience investigating cloud-native security events, such as IAM misconfigurations, insecure storage, compromised credentials, and unusual container behavior.
- Experience creating and maintaining detection rules and custom alerts .
- Experience using at least one SIEM platform and related log analysis tools.
- Familiarity with incident handling playbooks, security runbooks, and response procedures.
- Basic understanding of security practices related to Infrastructure as Code (IaC) and static code analysis tools.
Nice to Have:
- Experience working with SAP Cloud Infrastructure or other enterprise cloud environments.
- Experience improving SOC processes, detection capabilities, and incident response workflows.
Why we think you will love working here:
With us you count as a person, our doors are always open.
We live the Qualysoft Team Spirit and stand for transparency!
Fresh wind and new ideas are welcome, because standstill is a foreign word at Qualysoft.