- Страна
- Германия
Откликайтесь
на вакансии с ИИ

Senior SOC Engineer
Отличная вакансия в топовом финтехе с сильным инженерным брендом. Предлагается современный стек технологий, релокационный пакет и расширенный соцпакет, включая бюджет на обучение.
Сложность вакансии
Высокая сложность обусловлена требованиями к глубоким знаниям AWS, опыта работы с Google SecOps и навыков Infrastructure as Code (Terraform). Роль предполагает лидерство в проектировании сложных пайплайнов данных и автоматизации SOC.
Анализ зарплаты
Зарплата в объявлении не указана, но для позиции Senior Security Engineer в Берлине рыночный диапазон составляет 85,000–110,000 евро в год. N26 обычно предлагает конкурентоспособные зарплаты, соответствующие верхним границам рынка для опытных специалистов.
Сопроводительное письмо
I am writing to express my strong interest in the Senior SOC Engineer position at N26. With over five years of experience in security engineering and a deep focus on building scalable AWS logging pipelines, I am confident in my ability to enhance N26's security visibility and automation capabilities. My background in managing complex data ingestion workflows and my proficiency with Terraform and Python align perfectly with your team's mission to evolve cloud-based logging platforms.
In my previous roles, I have successfully integrated SIEM systems with ITSM tools and mapped detection capabilities to the MITRE ATT&CK framework. I am particularly excited about the opportunity to work with Google SecOps (Chronicle) and support purple team exercises at N26. My experience in automating data validation and log onboarding ensures that I can contribute to the reliability and effectiveness of your SOC operations from day one.
I admire N26's commitment to reimagining banking through technology and design. I am eager to bring my technical expertise in cloud infrastructure and deceptive security technologies to a diverse and innovative team in Berlin. Thank you for considering my application; I look forward to the possibility of discussing how my skills can support N26's security goals.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в n26 уже сейчас
Присоединяйтесь к команде N26 и станьте лидером в создании передовых систем безопасности для одного из самых успешных финтех-единорогов Европы!
Описание вакансии
About the Opportunity
We are seeking a Senior / Lead SOC Platform Engineer to own and evolve the cloud-based logging and automation platforms that power our Security Operations Center. Our SOC Engineering team does design scalable AWS logging pipelines and manage ingestion into Google SecOps, and believes in proactive security, automation, and continuous improvement to stay ahead of evolving threats. In this role, you will lead key initiatives that strengthen visibility, automation, and detection capabilities across the organization
*This is a Hybrid role based in Berlin or Barcelona.*
In This Role, You Will:
- Lead SOC engineering initiatives including SOC automation, SIEM–IT Service Management (ITSM) integration, and threat framework mapping and adoption (e.g., MITRE ATT&CK).
- Own data ingestion workflows for the Security Information and Event Management (SIEM) system and ensure high-quality, reliable telemetry.
- Support and integrate deceptive security technologies and participate in purple team exercises to enhance visibility and detection coverage.
- Collaborate with detection engineering, incident response, cloud teams, and security leadership to improve platform reliability and SOC effectiveness.
What You Need to Be Successful
Background:
- 5+ years of experience in SOC engineering, security engineering, cloud engineering, or platform engineering.
- Proven experience designing and operating large-scale logging pipelines in cloud environments.
- Strong understanding of SOC operations, detection workflows, and modern telemetry requirements.
Skills:
- Deep hands-on experience with AWS (S3, IAM, Lambda, Kinesis, CloudWatch, Step Functions, Glue, Athena, Glacier).
- Expertise with SIEM ingestion pipelines, ideally Google SecOps (Chronicle) with S3 ingestion.
- Strong understanding of log structures (JSON, CloudTrail, VPC Flow Logs, Syslog) and schema normalization.
- Proficiency with Infrastructure as Code (Terraform preferred).
- Strong scripting/programming skills (Python, Bash).
- Experience automating data validation, log onboarding, and pipeline health checks.
- Familiarity with MITRE ATT&CK mapping workflows using Navigator.
- Exposure to deceptive security technologies and telemetry pipelines.
- Experience supporting purple team exercises from a telemetry and engineering perspective.
Nice to Haves
- Google SecOps(Chronicle) engineering experience.
- Experience implementing automation for next-generation or Agentic SOC capabilities.
- Experience with deception frameworks (e.g., Canary, Thinkst, IllusionBLACK).
What’s in it for you:
- Accelerate your career growth by joining one of Europe’s most talked about disruptors 🚀.
- Employee benefits that range from a competitive personal development budget, work from home budget, discounts to fitness & wellness memberships, language apps and public transportation.
- As an N26 employee you will have access to a Premium subscription on your personal N26 bank account. As well as subscriptions for friends and family members.
- Additional day of annual leave for each year of service.
- A high degree of autonomy and access to cutting edge technologies - all while working with a friendly team of peers of diverse nationalities, life experiences and family statuses.
- A relocation package with visa support for those who need it.
Who we are
N26 has reimagined banking for today’s digital world. Technology and design empowereverything we do and it’s how we are building the global banking platform the world loves to use.
We've eliminated physical branches, paperwork, and hidden fees for an elegant digital experience and supreme savings. Giving people the power to live and bank their way is what gets us out of bed in the morning and inspires the work that we do.
We are headquartered in Berlin with offices in multiple cities across Europe, including Vienna and Barcelona, and a 1,500-strong team of more than 80 nationalities.
Sounds good? Apply now for this position.
Equal Opportunities:
We recognize that our strength lies in our people and the varied perspectives they bring to our workforce. We strive to build talented and diverse teams to drive our business success and empower our people to reach their full potential.
We genuinely welcome and encourage applications from people of all backgrounds, cultures, genders, sexual orientations, abilities, neurodiversities, and ages. We're committed to creating an inclusive workspace where everyone feels valued and respected, free from harassment and discrimination. If there's anything you need to make the application process work for you, please let us know by reaching out to candidate.exp@n26.com.
Visit our website to learn more about Diversity, Equity, & Inclusion at N26.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- AWS
- Amazon S3
- AWS IAM
- AWS Lambda
- Amazon Kinesis
- Amazon CloudWatch
- AWS Step Functions
- AWS Glue
- Amazon Athena
- Terraform
- Python
- Bash
- Google SecOps
- Chronicle
- SIEM
- MITRE ATT&CK
- JSON
- CloudTrail
- VPC Flow Logs
- Syslog
Возможные вопросы на собеседовании
Вакансия требует опыта работы с крупномасштабными пайплайнами логов в AWS.
Опишите ваш опыт проектирования и масштабирования конвейеров обработки данных в AWS с использованием Kinesis и Lambda для целей безопасности.
N26 использует Google SecOps (Chronicle) для SIEM.
Какие основные сложности возникают при нормализации данных и интеграции S3-хранилищ с Google SecOps, и как вы их решали?
Роль включает автоматизацию и использование Terraform.
Как вы организуете процесс тестирования и валидации изменений в инфраструктуре безопасности при использовании Terraform?
Упоминается участие в Purple Team и использование MITRE ATT&CK.
Расскажите, как вы использовали фреймворк MITRE ATT&CK для приоритизации разработки новых правил детекции и закрытия пробелов в видимости.
Вакансия предполагает внедрение технологий обмана (deception technologies).
Каков ваш подход к интеграции телеметрии от систем-приманок (honeypots) в общий процесс мониторинга SOC, чтобы минимизировать ложные срабатывания?
Похожие вакансии
Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)
Старший эксперт SIEM
Старший инженер внедрения SIEM
Pentester (Offensive Security)
Специалист по информационной безопасности
Application security specialist
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Германия