Security Operations Engineer (Full remote)
Bridge351 is a tech company focused on excellence, innovation and tailored solutions, operating across Europe in areas like Cloud, Cybersecurity, Data and Advanced Development.
About the Role
We're looking for a Security Operations Engineer to join Information Security Risk and Compliance (ISRC), the team responsible for embedding security and compliance across a cloud-native platform that powers software product development for the energy sector.
The platform is a hybrid-cloud, service-oriented environment giving application teams self-service capabilities across infrastructure, data, delivery, and operations. ISRC ensures this platform — and everything built on it — stays secure, resilient, and trustworthy.
You'll work at the intersection of SecOps tooling, detection engineering, and incident response, building the systems and automation that keep the platform's security operations sharp and scalable.
What You'll Do
SecOps Tooling Engineering
Design and build SecOps tooling as part of the broader security tool ecosystem
Develop architecture patterns and solution designs for SIEM, SOAR, vulnerability detection & management, EDR, logging pipelines, and user behavior analytics
Evaluate and integrate new tools and platforms to strengthen detection, response, and automation
Build and maintain scalable data ingestion, correlation, and alerting workflows
Automate repetitive security operations tasks — playbooks, scripts, and workflows (e.g., in SOAR tools)
Help shape a structured 24x7 security operations capability
Incident Response
Provide technical support during incidents, focusing on tooling, data quality, and engineering fixes
Improve detection content, correlation rules, dashboards, and data models based on real incident patterns
Support rapid instrumentation, log onboarding, and custom tooling during active security events
Detection Engineering
Develop, test, and operationalize new detection capabilities based on evolving threats and platform telemetry
Create and maintain detection-as-code artifacts (Sigma, YARA, KQL, static analysis rules)
Validate detection quality through adversary simulation and purple-teaming
Keep rules documented, version-controlled, and validated against production data
What We're Looking For
Must-have:
5+ years of experience in security operations, engineering, and cloud security tooling
Hands-on experience with SIEM/SOAR, EDR platforms, log ingestion, and telemetry pipelines
Scripting proficiency (Python, PowerShell, or Go)
Experience with infrastructure-as-code, CI/CD toolchains, and Kubernetes
Familiarity with threat modeling, detection engineering frameworks, TTP matrices, and MITRE ATT&CK
Experience creating architectural diagrams, interface specs, and onboarding guides
Experience with logging and detection for cloud architectures
Fluent English (C1 or above)
Nice-to-have:
Experience with Wazuh
Familiarity with observability platforms / OpenTelemetry
Background as a SOC Analyst (Tier 1–3) or solid understanding of SOC operations
Knowledge of security frameworks (BSI, ISO 27001, MITRE ATT&CK, etc.)
Experience with GCP or another public cloud provider
DFIR / blue team certifications (CySA+, GIAC, GCIH, BTL)
Kubernetes security certification (CKS or CNCF-related)
Location: Remote from EU (Travels to Germany foreseen)
Type: Full-time
Sector: Energy
- Departamento
- Cyber Security
- Role
- Security Operations
- Locations
- Bridge351 Europe
- Remote status
- Fully Remote