A

Security Engineer (SOC) (m/w/d)

APT-ONE GmbH

Remote · Berlin, State of Berlin, GermanyFull Time€80k+
RemoteConsulting
Apply with OnJob Free profile · takes about a minute

Security Engineer (SOC) (m/w/d) at APT-ONE GmbH is a full time role based in Remote · Berlin, State of Berlin, Germany (remote). The listing states pay of €80k+. Listed skills: Remote and Consulting. It was published on 1 September 2026 and was open at last check.

Security Engineer (SOC) (m/w/d) at APT-ONE GmbH — key details
RoleSecurity Engineer (SOC) (m/w/d)
CompanyAPT-ONE GmbH
LocationRemote · Berlin, State of Berlin, Germany (remote)
Employment typeFull Time
Pay (as listed)€80k+
Skills listedRemote and Consulting
Published1 September 2026
StatusOpen at last check

Die APT-ONE GmbH in Berlin ist ein auf Cyber Security spezialisiertes Beratungshaus. Wir schützen die IT-, OT-, Cloud- und KI-Systeme unserer Kunden wirksam vor digitalen Bedrohungen.

Unser Ansatz ist anders: KI-gestützte Werkzeuge übernehmen Discovery, Routine-Analysen und Mustererkennung – unsere Berater:innen validieren, interpretieren und konzentrieren sich auf Strategie und maßgeschneiderte Lösungen. Das ergibt tiefere Analysen und belastbare Entscheidungsgrundlagen in kürzerer Zeit, bei 40–60 % weniger Aufwand für Routinearbeit.

KI nur mit höchster Sensibilität für Kundendaten: Datenschutz steht über jedem Effizienzgewinn. KI ausschließlich auf vertraglich abgesicherten, datenschutzkonformen Plattformen, minimierte und anonymisierte Daten, niemals Kundendaten im Modelltraining. Diesen Umgang – und die Bereitschaft, unsere Prozesse und Produkte kontinuierlich mit KI weiterzuentwickeln – erwarten wir von allen Berater:innen.

Schwerpunkt dieser Rolle ist Detection Engineering: SIEM- und XDR-Plattformen, Log-Qualität, Detectionas-Code und Automatisierung – sicher in KQL, Sigma und MITRE ATT&CK.

Bei uns bist du richtig, wenn:

  • du ein attraktives Fixgehalt plus überdurchschnittliche Gewinnbeteiligung willst.
  • du ortsunabhängig an hochrelevanten Projekten in Security Operations und KI-Sicherheit arbeiten willst.
  • du KI als Hebel siehst und Sicherheitsberatung neu denken willst – ohne Kompromisse beim Datenschutz.
  • du deine Expertise in SOC-Plattformen, Detection Engineering und Automatisierung ausbauen willst.

Aufgaben

  • Aufbau, Betrieb und Weiterentwicklung von SOC-Plattformen (SIEM, SOAR, EDR/XDR)
  • Onboarding neuer Logquellen inklusive Parsing, Normalisierung und Sicherstellung der Datenqualität
  • Entwicklung und Optimierung von Detection-Regeln und Use Cases (Sigma, KQL, SPL) auf Basis von MITRE ATT&CK
  • Automatisierung von Analyse- und Response-Prozessen durch Playbooks und Skripting (Python, PowerShell)
  • Aufbau von Detection-as-Code-Pipelines inkl. Versionierung, Testing und CI/CD
  • Integration und Operationalisierung von Threat Intelligence
  • Enge Zusammenarbeit mit Analyst:innen und Incident Respondern zur Reduktion von False Positives und Verbesserung der Detection-Qualität
  • Technische Unterstützung bei Sicherheitsvorfällen
  • Erstellung von Runbooks, Use-Case-Dokumentationen und technischen Konzepten
  • Einsatz KI-gestützter Werkzeuge für Log-Analyse, Regel- und Playbook-Entwürfe sowie Dokumentation – inklusive fachlicher Validierung und Freigabe der Ergebnisse

Qualifikation

  • Souveräner Umgang mit KI-Werkzeugen im Beratungsalltag inkl. kritischer Bewertung der Ergebnisse
  • Ausgeprägtes Bewusstsein für Vertraulichkeit beim KI-Einsatz: Du weißt, welche Daten in welches System dürfen, und kennst die Risiken (Datenabfluss, Modelltraining, Prompt Injection)
  • Bereitschaft, Prozesse und Produkte kontinuierlich KI-basiert weiterzuentwickeln
  • Mindestens 5 Jahre Erfahrung in IT-/Cyber-Security, davon mehrere Jahre in Architektur- oder Beratungsrollen
  • Breites Technologieverständnis über Netzwerk, Endpoint, Identity, Applikation und Cloud
  • Erfahrung mit Zero-Trust- und Segmentierungskonzepten sowie IAM/PAM (Entra ID, Active Directory)
  • Sicherer Umgang mit ISO 27001, BSI IT-Grundschutz, NIST CSF, MITRE ATT&CK, SABSA/TOGAF
  • Kenntnisse in Kryptografie, PKI und sicherem Applikationsdesign
  • Verhandlungssichere Deutsch- und Englischkenntnisse

Von großem Vorteil:

  • Cloud-Architekten-Know-how: Design, Absicherung und Betrieb von Cloud- und Hybrid-Umgebungen (Azure, AWS, GCP), Cloud-native Security-Dienste, Infrastructure-as-Code
  • Erfahrung mit Prompt Engineering, KI-Agenten oder LLM-Integration in Workflows
  • Kenntnisse in KI-Governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM)
  • Erfahrung in regulierten Umgebungen (KRITIS, Finanzsektor, Industrie/OT)

Zertifizierungen (nice to have):

OffSec (Hands-on & Offensive/Defensive Integration)

  • OSDA (Defense Analyst – SOC-200)
  • OSCP (PEN-200)
  • SANS / GIAC (Architektur & Tactical Detection)
  • GCDA (SANS SEC555)
  • GDSA (SANS SEC530)
  • GCIH (SANS SEC504)

Ergänzende Profil-Schärfung

  • SANS SEC586 (Blue Team Automation)
  • Microsoft SC-200

Benefits

  • Fixgehalt ab 80.000 € plus Gewinnbeteiligung bis zu 70.000 €
  • Flexible Arbeitszeiten, Remote-Arbeit, 30 Tage Urlaub
  • IT-Equipment wie Apple MacBook
  • Regelmäßige Teamevents
  • Betriebliche Altersvorsorge und Krankenversicherung, Shopping- und Mitarbeiterrabatte

Werde Teil von APT-ONE und mach Sicherheit zu deiner Mission

Share:WhatsAppLinkedIn

Create your free OnJob profile to apply — we'll take you to APT-ONE GmbH's application after sign-up. · Posted 1 Sept 2026.

Security Engineer (SOC) (m/w/d) at APT-ONE GmbH — questions answered

What does the Security Engineer (SOC) (m/w/d) role at APT-ONE GmbH pay?

The Security Engineer (SOC) (m/w/d) at APT-ONE GmbH listing states pay of €80k+ for the Remote · Berlin, State of Berlin, Germany (remote) position. That figure is taken directly from the employer's own posting as published, not estimated or averaged from other roles.

Is the Security Engineer (SOC) (m/w/d) role at APT-ONE GmbH remote?

Yes — APT-ONE GmbH advertises this Security Engineer (SOC) (m/w/d) role as remote, tied to Remote · Berlin, State of Berlin, Germany, and it is listed as full time work. Remote terms come from the employer's own posting, so confirm the expected working hours, timezone and any on-site days with APT-ONE GmbH before you apply.

What skills does the Security Engineer (SOC) (m/w/d) role at APT-ONE GmbH require?

The Security Engineer (SOC) (m/w/d) at APT-ONE GmbH listing names Remote and Consulting. Those are the skills the employer put on the posting itself, so they are the ones worth matching in your profile and covering first in an interview.

Is the Security Engineer (SOC) (m/w/d) role at APT-ONE GmbH still open?

The Security Engineer (SOC) (m/w/d) posting at APT-ONE GmbH was open at OnJob's last check of the employer's careers page, having been published on 1 September 2026. OnJob re-checks source listings on each build and marks a role closed once it disappears, but listings can close without notice, so the employer's own page is the final word.

How do you apply for the Security Engineer (SOC) (m/w/d) role at APT-ONE GmbH?

Apply to the Security Engineer (SOC) (m/w/d) at APT-ONE GmbH role through OnJob with a free profile: OnJob scores your fit against the listing, shows the skills lowering that score, and submits an ATS-ready profile to APT-ONE GmbH's own application page. Creating a profile is free and needs no card.

Explore more on OnJob

Hiring for a role like this?

Post a job on OnJob and reach AI-matched candidates.

Post a Job