q.beyond AG
Köln
Work experience
Senior, very experienced
q.beyond AG is a leading German IT service provider. Our 1,100 employees with expertise in cloud, SAP, Microsoft, data intelligence, security and software development support our SME customers in their digital transformation.
Design future-proof IT solutions with us as Senior SOC Engineer (m/f/d) – Focus SIEM (Splunk / Microsoft Sentinel) at one of our locations:
- Operation, maintenance, and further development of our SIEM landscape (Splunk and Microsoft Sentinel)
- Development, implementation, and tuning of use cases, correlations, and detection rules
- Integration of new log sources (e.g., firewalls, EDR, cloud, identity systems)
- Automation and optimization of processes in security monitoring and incident response
- Support SOC analysts in investigations and incident handling
- Contribute to the further development of our use case catalog and detection framework
- Monitoring, troubleshooting, and performance optimization of the SIEM infrastructure
- Close collaboration with our analyst team
- Work-life balance: Flexible mix of working hours and work location (40% home office) for a harmonious work-life integration.
- Vacation entitlement: 30 days of vacation, special leave and a sabbatical account for restful time off and relaxation.
- Quality of life: private accident insurance, supplementary health insurance, extended sick pay and a company pension scheme. Focus on your mental health through the Fürstenberg Institute.
- Fitness promotion: Own JobRad, virtual physiotherapy, various company running events.
- Career opportunities: Numerous certification opportunities via Udemy, Linkedin Learning and SAP Learning Hub.
- Professional and personal development: Our internal Academy, monthly company Learning Days, development dialogs and a leadership development program.
- Family first: Baby welcome package and €1,000 bonus for the birth.
- Flitzpiepen: Daycare center closed? Don't worry - there are family-friendly workplaces with play facilities for your offspring.
- Dog Office: Office space where dogs are welcome, for a relaxed working atmosphere.
Some of our benefits are location-based.
- Several years of experience in SOC or SIEM environments
- Excellent knowledge of Splunk (Search Processing Language, CIM, dashboards, apps)
- Experience with Microsoft Sentinel and KQL (Kusto Query Language)
- Solid expertise in onboarding log sources (Syslog, CEF, API, agent-based)
- Experience in developing detection rules and use cases
- Good understanding of network, Windows, Linux, and cloud logs
- Knowledge of scripting/automation (Python, PowerShell, REST API) is an advantage
- Analytical thinking, structured work approach, and enjoyment of teamwork
- Fluent in German (C1) and English (B2)
You can apply quickly and easily without a cover letter. Simply upload your CV and certificates online on our job portal.
Inclusion is important to us. We explicitly welcome applications from people with severe disabilities and those with equivalent status.
CONTACT
Your personal contact Rocio will be happy to answer your questions and comments.
q.beyond AG
Talent Acquisition
Rocio Romera del Moral
Rocio Romera del Moral
Employee
I agree that external content is displayed to me. This means that personal data is transmitted to third-party platforms. q.beyond AG has no influence on this. You can read more about this in our privacy policy. You can deactivate the display at any time.
You can disable such external embeddings with this switch(data protections).
#content_zone { max-width: 834px; } #scheme_detail_data { width:100%; display:table; margin-bottom: 10px; } .scheme-border { border: 1px solid rgba(220,223,226,0.8); } .scheme-margin { margin-top: 10px; } .scheme-display .scheme-content { font-size: 16px; padding: 14px 24px; background-color: #ffffff; line-height: 1.6; } .scheme-display .scheme-title { word-break: break-word; } .scheme-display .scheme-title h2 { margin: 0px; font-size: 28px; line-height: 2; padding: 0px; } .scheme-display .scheme-title ul { margin-bottom: 16px; } .scheme-display .video { width: 100%; height: 400px; } .scheme-display h2.scheme-headline { margin: 0px 0px 18px 0px; padding: 0px; } .scheme-display .content-images { position: relative; overflow: hidden; display: block; box-sizing: border-box; padding: 0px; } .scheme-display .content-images:not(:has(.content-images-frame)) { height: 335px; } #header_image { display: none; } #jobTplContainer ul.scheme-additional-data { margin-bottom: 0px; min-width: 40%; } .scheme-additional-data { float: left; margin: 0; padding: 0; list-style: none; } .scheme-additional-data li { list-style: none; margin: 4px 15px 0px -3px !important; } .scheme-additional-data li.left { float: left; } .scheme-display .slide-images:nth-child(2), .scheme-display .slide-images:nth-child(3) { display:none; } .scheme-display .slide-images { width: 100%; position:absolute; top: 50%; left: 50%; -webkit-transform: translate(-50%,-50%); -ms-transform: translate(-50%,-50%); } .scheme-display .content-images-frame { position: relative; width: 100%; height: 335px; overflow: hidden; } .scheme-display .content-images-description { display: block; text-align: left; font-size: 1rem; line-height: 1.4; color: #000; padding: 8px 24px; border-bottom: 1px solid rgba(220,223,226,0.8); } .scheme-content .user-image { width: 100px; height: 100px; border-radius: 50%; float: left; line-height: 100px; background: no-repeat center center; background-size: cover; } .scheme-content .user-data { height: 100px; margin-left: 80px; } .scheme-content .user-data li { list-style: none; } i.fa-fw { margin-right: 5px; margin-left: 5px; } @media (max-width: 768px) { .scheme-additional-data li { display: block; float: none; } .scheme-display .content-images { height: 250px; } } @media (max-width: 650px) { .scheme-display .content-images { height: 250px; } } @media (max-width: 450px) { .scheme-display .content-images { height: 133px; } } #frame_zone { background-color: #ffffff; }