StellenbeschreibungppThe AO is a medically guided, not-for-profit organization, a global network of surgeons, and the world's leading education, innovation, and research organization specializing in the surgical treatment of trauma and musculoskeletal disorders. We are home to people from all over the world, from different backgrounds, with diverse talents and specialist areas. What binds us together is our passion for excellence, our dedication to our mission of improving patient care, and our understanding that we are stronger together: we are one AO. /ppFor more information, visit: /ph3Senior IT Security Engineer (ID2140) /h3h3Short Description /h3pWe are seeking a Security Engineer to lead the automation of SOC Level 1 and Level 2 processes and support advanced incident response. This role is critical to future security operations. The engineer will design, implement, and maintain automated runbooks using Microsoft's security technologies and AI capabilities, ensuring scalable and efficient security operations. /ph3Main Responsibilities /h3ulliDevelop and maintain automated SOC Level 1 and Level 2 runbooks and playbooks using Logic Apps, Power Automate, and AI Foundry components /liliEngineer detection rules, workbooks, and playbooks in Microsoft Sentinel/Microsoft XDR platforms /liliIntegrate and optimize Microsoft Defender for Endpoint, Identity, Cloud, and Office 365 within the XDR framework /liliApply AI-driven threat detection and response using Microsoft Copilot for Security and related tools /liliCollaborate with internal teams and external partners to embed security into CI/CD pipelines and IT delivery models /liliProvide SOC Level 3 support for complex incidents, including forensic analysis and threat containment /liliContribute to the DevSecOps organization /liliSupport the implementation of an ISO 27000-aligned ISMS and assist with governance and compliance efforts /li /ulh3Main Requirements /h3ulliBachelor's degree in Information Technology, Computer Science, or related field /lili5 years of professional experience in relevant field /liliMinimum 2 years of hands-on experience with SOC Level 1 and Level 2 operations and Level 3 incident response /liliProgramming skills in Python or Powershell /liliDeep familiarity with Microsoft security products, including Microsoft Sentinel, Defender XDR components and KQL /liliStrong understanding of Azure infrastructure, identity, and security architecture /liliUnderstanding of security baselining, network hardening, and zero trust principles /liliAbility to work in cross-functional DevSecOps environment /liliFluency in English. Fluency in German or any other languages will be considered as an added value /li /ulh3Preferred Qualifications /h3ulliMicrosoft certifications in security technologies (e.g., SC-200, SC-300) /liliExperience with agentic AI standards and responsible AI practices /liliFamiliarity with governance models and risk assessment frameworks /liliUnderstanding of structured threat intelligence and enrichment workflows /liliFamiliarity with MITRE ATTCK mapping and detection coverage assessments /liliFamiliarity with detection-as-code pipelines and version control systems /liliFamiliarity with Web Application Firewall (WAF) principles and rule tuning /li /ululliAn interesting and varied job in an exciting and innovative organization /liliThe opportunity to be part of a highly committed international team /liliModern infrastructure /liliHigh degree of flexibility regarding working hours and location (depending on operational requirements) /liliGenerous pagacke of social benefits, including supplementary vacation days and pension scheme contributions /liliInternal skills training opportunities and support for continued education /li /ul /p #J-18808-Ljbffr