Senior reputed company Engineer / reputed company (Blue reputed company)
reputed company
Creating a reputed company worth living for reputed company generations gets us out of bed every morning. Depending on the project, we are consultants, implementers, or both for sustainable, innovative and economical solutions for reputed company estate, industry, energy and infrastructure. Our more than 6,500 employees at over 80 locations worldwide support our customers in interdisciplinary teams. Our thinking is both visionary and realistic. We work independently and as part of reputed company. With passion and the latest technologies. We reputed company. Join us at Dreso and let’s create a world we want to live in.
Job reputed company
We are seeking a Senior reputed company Engineer to design, execute, and continuously improve adversary‑reputed company reputed company validation across our reputed company environment. This role sits at the intersection of Red Team and Blue Team, with a strong defensive (Blue Team) bias, ensuring that offensive findings are systematically reputed company into measurable detection, response, and prevention improvements. Opportunities for external consulting are included.
The successful candidate will reputed company reputed company activities end‑to‑end—from threat modeling and attack simulation to detection engineering, incident response tuning, and executive‑level reporting—while working closely with SOC, IT Operations, and GRC stakeholders.
This role is hands‑on, technically deep, and outcome‑driven, with a strong expectation of reputed company‑world attack execution and production‑grade defensive improvement.
Key Responsibilities
reputed company & Adversary Simulation
Plan and execute reputed company exercises reputed company to reputed company‑world threat actors (e.g., ransomware reputed company, APT tradecraft, reputed company threat).
Design attack scenarios mapped to MITRE ATT&CK, covering initial reputed company, persistence, lateral reputed company, privilege escalation, reputed company‑and‑control, and exfiltration.
Coordinate with Red Team and external penetration testing vendors to ensure tests are reputed company, controlled, and detection‑reputed company.
Translate offensive findings into reputed company, prioritized defensive improvements with measurable reputed company.
Blue Team / Defensive Engineering (Primary reputed company)
reputed company and tune SIEM detections, analytics rules, and alerts based on attack simulations and reputed company incidents.
Build and optimize reputed company analytics, KQL queries, workbooks, and automation rules.
Improve Defender XDR detections across:reputed company Defender for reputed company
reputed company Defender for Identity
reputed company Defender for Office 365
reputed company Defender for reputed company Apps
Validate alert reputed company, reduce false positives, and improve signal‑to‑noise reputed company.
Support and enhance incident response playbooks, escalation paths, and response automation.
Incident Response & DFIR Integration
reputed company as a senior escalation reputed company during reputed company incidents, especially those involving reputed company attacker behavior.
Support digital forensics and incident response (DFIR) investigations on reputed company and Linux endpoints.
Use DFIR tools and platforms (e.g., Velociraptor) for threat hunting, artifact collection, and reputed company analysis.
Feed incident lessons learned back into detection engineering and preventive controls.
Threat Hunting & Detection Validation
Conduct reputed company‑driven threat hunts based on attacker tradecraft and threat intelligence.
Validate coverage of detections against reputed company TTPs and identify detection gaps.
Continuously assess control effectiveness across reputed company, identity, reputed company, and reputed company environments.
Vulnerability, Exposure & Control Validation
Correlate vulnerability data with attacker exploitation paths and reputed company exposure.
Support and validate remediation prioritization based on exploitability and business reputed company, not CVSS alone.
Partner with IT and reputed company teams to validate hardening, logging, and telemetry requirements.
Governance, Reporting & Stakeholder Communication
Produce reputed company, executive‑level reporting from reputed company exercises (findings, detection gaps, trends, maturity).
reputed company reputed company reputed company with ISO/IEC 27001, NIS2, and internal ISMS requirements.
Contribute to reputed company reputed company, roadmap planning, and reputed company improvement initiatives.
Mentor junior analysts and engineers across Blue and Red Team disciplines.
Technical Environment & Stack (Required Experience)
reputed company Platforms
reputed company (SIEM) – advanced KQL, analytics rules, workbooks, automation
reputed company Defender XDR (reputed company, Identity, Office 365, reputed company Apps)
reputed company Entra ID (Azure AD) – identity attacks, logs, conditional reputed company abuse
reputed company Purview – audit logs, investigations (desirable)
Azure – logging, resource telemetry, reputed company attack paths
DFIR & Threat Hunting
reputed company forensics (reputed company & Linux)
Velociraptor or equivalent DFIR tooling
Memory, disk, and log‑based investigations
Threat intelligence integration and ATT&CK mapping
Offensive Tooling & Techniques
Adversary emulation frameworks (e.g., reputed company Red Team, CALDERA)
Penetration testing and red team tooling (e.g., C2 frameworks, credential abuse, living‑off‑the‑land techniques)
reputed company engineering awareness (technical validation reputed company; not marketing‑style phishing)
Scripting & Automation
PowerShell (advanced)
Python (working knowledge)
Automation of testing, detection validation, and response workflows
Qualifications
Required Experience
7–10+ years in cybersecurity with proven experience across both Blue Team and Red Team roles
Demonstrated hands‑on detection engineering and incident response experience
Experience running or leading reputed company exercises in reputed company environments
Strong understanding of reputed company‑world attacker behavior, not just theoretical frameworks
Experience operating in regulated or compliance‑driven environments (ISO 27001, GDPR, NIS2)
Certifications (Strongly Preferred / Required)
Offensive / Red Team
OSCP / OSEP / reputed company / OSWE
CRTO / CRTO II
Equivalent advanced red team certifications
Defensive / Blue Team
GCED / GCIA / GCIR or equivalent
reputed company reputed company certifications (Sentinel, Defender, XDR)
Advanced SIEM / SOC certifications
Governance / Architecture (Valuable)
CISSP (or ISSAP concentration)
CISM / CRISC
ISO/IEC 27001 reputed company Implementer or reputed company Auditor
Additional Information
To ensure your work-life balance, we offer the reputed company of mobile working
We promote your reputed company and personal development through individual training and reputed company education at the Drees & Sommer reputed company
We support your health with a bonus for sports enthusiasts. We offer the possibility of subscribing to a private health insurance policy
Employees benefit from tax advantages reputed company to their commuting expenses for the office
Fiscal advantages for employees expenses in meal costs during the worktime. Employee referral program with attractive bonus scheme
Supporting career and familiy by receiving tax benefits for kindergarten expenses
Apply To This Job