Senior Security Engineer (SOC) (m,f,x)Active
The opportunity
We’re looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh’s security posture.
What you'll do
Responsible for maturing logging and monitoring of Cloud, IT and Application: workloads through automation and IaC
Filter, ingest and optimize security-specific events from large log streams: such as App logs, Kubernetes logs, CloudTrail, CloudFlare and ELB logs etc.
Conduct threat hunts against file-less malware and APTs by leveraging EDR, OS: and network telemetry acquired through specialized open-source tool set like Sysmon, Osquery, RITA and Zeek
AI-Enhanced Coding: Ability to use AI coding assistants to write scripts for security automation and data parsing and building detection logic.
Investigation Acceleration: Proficiency in using LLMs (e.g., Claude, ChatGPT, Gemini) to quickly summarize high-volume JSON logs, investigate and explain complex code snippets etc.
Develop advanced correlation and cross-correlation rules beyond what is: available out of the box to detect sophisticated attacks and fraud cases
What they're looking for
- Generate security metrics and reporting on incidents and effectiveness of the SOC operation
- Lead efficient Incident Detection and Response in AWS cloud and enterprise IT environments
- Shift Communication: Serve as the shift’s main communicator, updating Berlin SOC leadership and local IT/business stakeholders during active incidents.
- Playbook & Process Improvement: Suggest detection rule tuning, SOP refinements, and contribute to the team knowledge base to reduce false positives and improve workflows.