DevSecOps Engineer / Threat Hunter

Mam Gruppe — Germany · Posted ~2 hours ago

Senior Full-time

Skills

DevSecOps Security operations Threat hunting Detection engineering Security monitoring Google SecOps

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A security specialist is sought to operate and improve a security monitoring platform while developing detection rules and conducting proactive threat hunting across enterprise environments.

Highlights

Hands-on cybersecurity role combining platform engineering, threat detection, and proactive security investigation.

Description

DevSecOps Engineer / Threat Hunter | Berlin A well-established organisation is strengthening its security operations capability and has asked MAM Gruppe to help find a specialist to lead its Google SecOps environment. The focus is on getting ahead of attackers. The successful candidate will divide their time between engineering the platform and searching the environment for activity that has gone unnoticed. Expect a practical, hands-on remit within the security operations team. The role: Run the Google SecOps platform end to end, bringing new data sources on board, configuring parsers and data models, and closing gaps in telemetry quality.Translate knowledge of adversary techniques into detection rules and use cases, reviewing them regularly to keep noise low.Set the agenda for proactive hunting, forming hypotheses and following suspicious activity wherever it leads across the estate.Feed the findings from each hunt back into the detection library.Partner with SOC colleagues to raise the maturity of detection and response across the organisation. What you'll need: Hands-on engineering experience in Google SecOps (formerly Chronicle), including ingestion, parsing and data normalisation.Hunting experience driven by clear hypotheses and grounded in a detailed understanding of how adversaries operate, using MITRE ATT&CK as a practical reference.Confidence evaluating log sources and telemetry for completeness and reliability.A practical approach to writing and tuning detection logic, keeping alert volumes meaningful while leaving no important activity unwatched.Any of the following would strengthen your application: the wider Google Cloud security toolset, other SIEM/SOAR platforms or migration work between them, Python automation, relevant industry certifications, or experience in large-scale, high-traffic environments. How to apply: Interested? Get in touch with the MAM Gruppe team for a confidential conversation about this role.