Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Interval Group

Cyber Defence Analyst – SOC – Freelance

Interval Group

. Continuously monitor SIEM, SOAR, EDR and network security data .

Posted 10/8/2026contractGermanyMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security incident response, threat hunting, and log analysis, with a strong focus on optimizing SIEM and EDR solutions. Proficient in utilizing the MITRE ATT&CK Framework and ensuring compliance with security protocols and SLAs.

Highest-signal resume keywords
SIEM Solutions (Splunk, Microsoft Sentinel)EDR/XDR Technologies (Microsoft Defender for Endpoint, HarfangLab, Palo Alto)Incident Response and Security PlaybooksThreat Hunting and Detection EngineeringFluent German (C1) and Professional-Level English (B2)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Incident TriageLog Analysis (Syslog, Firewall, DNS, Proxy)Network Packet AnalysisIndicators of Compromise (IoCs)Tactics, Techniques and Procedures (TTPs)MITRE ATT&CK FrameworkNetwork ProtocolsWindows and Linux AdministrationActive Directory ManagementSecurity Incident Documentation
Tools & Technologies
SIEMSOAREDRMicrosoft Defender for EndpointSplunkMicrosoft SentinelHarfangLabPalo AltoThreat Hunting ToolsAutomated Incident Response Platforms
Certifications & Qualifications
Splunk Core Power UserCertified Cyber Defence AnalystMicrosoft AZ-900Microsoft SC-200Blue Team Level 1 or Level 2Palo Alto Networks XDR AnalystGIAC (GCIH, GCIA, GCFA)
Industry Keywords
SOC AnalystCyber Defence AnalystSecurity Operations AnalystMSSPEnterprise SOCSecurity SLAsSecurity-Critical EnvironmentsHighly Regulated EnvironmentsIncident ResponseEscalation Processes

Tech Stack

Tools & technologies
DNSLinuxSplunk

About the role

Key responsibilities & impact
  • Continuously monitor SIEM, SOAR, EDR and network security data
  • Analyse, qualify and prioritise incoming security alerts
  • Distinguish between false positives and genuine security incidents
  • Carry out initial incident response and containment measures in accordance with established playbooks
  • Analyse firewall, DNS, proxy, authentication and endpoint logs
  • Proactively conduct threat hunting based on Indicators of Compromise (IoCs) and Tactics, Techniques and Procedures (TTPs)
  • Investigate attack patterns using the MITRE ATT&CK Framework
  • Optimise SIEM/EDR detection rules and security playbooks
  • Document security incidents and prepare incident reports
  • Ensure structured escalation processes and shift handovers
  • Support compliance with defined security SLAs

Requirements

What you’ll need
  • 3+ years of professional experience as a SOC Analyst, Cyber Defence Analyst or Security Operations Analyst
  • Proven experience in an MSSP or enterprise SOC environment
  • Hands-on experience with SIEM solutions such as Splunk or Microsoft Sentinel
  • Experience with EDR/XDR technologies such as Microsoft Defender for Endpoint, HarfangLab or Palo Alto
  • Very good knowledge of network protocols, Windows, Linux and Active Directory
  • Experience analysing Syslog, firewall, DNS, proxy and authentication logs
  • Experience with security incident triage and basic network packet analysis
  • Good knowledge of the MITRE ATT&CK Framework
  • Experience with incident response, security playbooks and escalation processes
  • Fluent German (C1 or higher) and professional-level English (at least B2)
  • Clean criminal record
  • Ability to obtain and maintain the required German/European security clearances
  • Residence in Europe
  • Eligibility for the required German/European security clearances
  • A Europass CV is desirable but not required
  • Preferred: Splunk Core Power User or Certified Cyber Defence Analyst
  • Preferred: Microsoft AZ-900 or SC-200
  • Preferred: Blue Team Level 1 or Level 2
  • Preferred: Palo Alto Networks XDR Analyst
  • Preferred: GIAC certifications such as GCIH, GCIA or GCFA
  • Preferred: Experience with SOAR platforms and automated incident response processes
  • Preferred: Experience with threat hunting and detection engineering
  • Preferred: Experience in security-critical or highly regulated environments

Benefits

Comp & perks
  • Flexible working hours
  • Freedom to select projects independently
  • Access to exciting projects across various industries
  • Support for professional development
  • Attractive compensation
  • Support from a dedicated team
  • Independent working environment
  • Access to a strong professional network