You advise clients from requirements gathering through architecture and PoC to successful implementation.
Your focus: SIEM and XDR solutions that deliver measurable value — transparent, documented, and cleanly transitioned into operation.
Capture requirements, define use cases, and create solution architectures (HLD/LLD) for SIEM and XDR deployments
Implement, configure and test (including data source onboarding, parsers/connectors, detection rules, dashboards)
Plan, execute and evaluate proofs of concept and translate findings into actionable recommendations
Onboarding into managed services: use-case catalog, playbooks/runbooks, handover to operations including KPIs/SLAs
Create and maintain documentation (operations manual, architecture and interface documents, CRM)
Provide technical support to sales (demos, presentations, RFPs) and conduct customer training
Travel within the D‑A‑CH region (Germany, Austria, Switzerland); extent depends on the project.
Requirements
IT qualification or degree, or equivalent professional experience; at least 2 years in consulting/architecture/administration with client contact
Practical experience with at least one SIEM (e.g., Logpoint, Splunk, Microsoft Sentinel, QRadar) and one XDR platform (e.g., Microsoft Defender, CrowdStrike, SentinelOne)
Experience in data integration (Syslog/API/agent), detection engineering (e.g., Sigma, KQL/EQL) and dashboarding/reporting
Advantageous: SOAR/automation, scripting (e.g., Python/PowerShell), basic knowledge of MITRE ATT&CK
Analytical, structured, self-motivated and team-oriented; strong communication and presentation skills
Very good German and very good English language skills
Willingness to work across regions and travel within the D‑A‑CH region
Tech Stack
Python
Splunk
Benefits
30 days of vacation plus additional days off on December 24 and December 31
Structured onboarding, clear development and career prospects
Modern work environment, transparent communication, short decision-making paths
Fitness subsidy: up to €30 gross per month
Bike leasing subsidy: €50 gross per month (up to two bikes possible)
DSL subsidy: up to €50 per month
Accident insurance: coverage for work-related and private incidents