Uney GmbH seeks a Cyber Security Operations Engineer to manage SOC platforms for SME clients, handling deployment, training, monitoring, and incident response in an on-site role in Switzerland.
The company is looking for a mid-level engineer to operate and deliver Security Operations Center (SOC) platforms as a managed service. This position focuses on deploying the platform, onboarding clients, providing technical training, and ensuring the system performs optimally while maintaining high service standards and client satisfaction.
Responsibilities
- Install and configure the SOC platform within new client environments, aligning settings with their specific network architecture.
- Set up log collection agents and data sources, then customize monitoring parameters to match client needs.
- Integrate existing security tools with the SOC platform and conduct thorough testing before launch.
- Document deployment architectures and configurations for future reference.
- Lead technical onboarding sessions and deliver customized training for client IT and security teams.
- Create user guides, video tutorials, and training materials to support client adoption.
- Demonstrate platform features, dashboards, and reporting capabilities during training sessions.
- Train clients on alert review processes, incident workflows, and response procedures.
- Conduct hands-on workshops and provide post-training support to ensure client readiness.
- Monitor security alerts and events across all client environments using AI detection engines.
- Analyze, triage, and investigate security incidents, performing initial analysis as needed.
- Execute incident response procedures in accordance with client Service Level Agreements (SLAs).
- Coordinate with clients during active security incidents and escalate critical issues to senior teams.
- Document all incidents, actions taken, and resolutions for record-keeping.
- Perform threat hunting using AI-powered analytics tools to identify potential threats.
- Serve as the primary technical contact for assigned clients, addressing inquiries via ticketing, email, and phone.
- Troubleshoot platform usage issues and provide technical guidance on security alerts.
- Manage client requests for configuration changes and ensure timely resolution within SLA parameters.
- Conduct regular client check-ins and service review meetings to gather feedback and improve service.
- Generate and deliver scheduled security reports (daily, weekly, monthly) tailored to client requirements.
- Create executive summaries of security posture and incidents, presenting findings in review meetings.
- Communicate security trends, threat intelligence insights, and platform performance metrics to clients.
- Document lessons learned and provide recommendations for continuous improvement.
Requirements
- Bachelor's degree in Information Security, Computer Science, IT, or a related field.
- 2-4 years of experience in SOC operations, security monitoring, or cybersecurity.
- Experience with SIEM platforms and security monitoring tools.
- Understanding of network security, endpoint security, and common attack vectors.
- Experience in customer-facing technical roles or managed services.
- Strong understanding of security operations workflows and incident response.
- Excellent communication skills (both verbal and written in English).
- Strong English proficiency (reading, writing, speaking).
- Willingness to work rotating shifts including nights, weekends, and holidays.
Nice to have
- CompTIA Security+, CySA+
- Certified Ethical Hacker (CEH)
- GIAC Security Essentials (GSEC)
- GIAC Certified Incident Handler (GCIH)
- Certified SOC Analyst (CSA)
- ITIL Foundation (for service management)
- Basic scripting knowledge (Python, PowerShell - advantage)
Quelle: öffentlich zugängliche Karriereseite des Arbeitgebers. Batchly ist nicht der Arbeitgeber und steht nicht notwendigerweise in einem Vertragsverhältnis mit dem Unternehmen.