Overview
Security Operations Center Engineer Jobs in Bucharest, Romania at Banca Transilvania
Title: Security Operations Center Engineer
Company: Banca Transilvania
Location: Bucharest, Romania
Your digital journey starts here!
Create. Grow. Deliver our story to millions.
#BTCode, where technology meets creativity. Code is our universal language and innovation is the fuel that propels us into the future. 🚀
We are expanding our Security Operations Center team and looking for a SOC Engineer to help strengthen our threat detection and incident response capabilities.
This role is focused on engineering, and involves designing, implementing, and continuously improving use cases for cyberattacks, enabling the SOC team to efficiently detect and respond to cyber threats.
You will work in a complex environment with multiple security and operational tools, playing a key role in integrating them into a cohesive and effective ecosystem.
If you’ll join our team, you will be challenged to:
- Design and develop SOC use cases based on MITRE ATT&CK and relevant threat scenarios.
- Correlate SIEM data from multiple sources to generate meaningful and actionable offenses in relation to each SOC use case.
- Involves collaborating with technical/security teams to ensure proper log collection, parsing, and data integration.
- Define incident triage and investigation workflows for SOC analysts (analysis steps, validation, severity criteria).
- Build and optimize response playbooks (SOAR automation) to support fast and effective threat containment.
- Support incident escalation toward internal teams or external incident response/forensics partners .
- Continuously improve detection use cases based on lessons learned from incidents, infrastructure or tooling changes, compliance or audit requirements.
- Contribute to defining and standardizing SOC procedures (SOPs).
- If needed, participate in war rooms, internal reviews, side projects, and initiatives requiring security expertise.
Why this role matters
- You will directly contribute to reducing detection and response time, a critical factor in minimizing the impact of cyberattacks.
- You will help maximize the value of existing security tools through proper integration and correlation.
- You will collaborate with multiple security and operations engineering teams as well as with SOC analysts; will be part of a team with high ambitions and strong connections; you will have the possibility to express your ideas, exercise/work on your skills and leave a mark in the organization.
- You will operate on best-in-class technologies and in a challenging environment.
To perform in this role, we would like you to have:
- Solid experience in cybersecurity, preferably within SOC or detection/automation engineering roles.
- Hands-on experience with SIEM platforms (e.g. QRadar, XSIAM, Splunk, Microsoft Sentinel,), SOAR / automation tools (e.g., Cortex XSOAR), log analysis and event correlation.
- Good understanding of the MITRE ATT&CK framework.
- Proven experience in working with multiple security technologies (network, endpoint, WAF, monitoring tools, etc.)
- Ability to design relevant operating procedures, focusing on reducing noise and false positives, but also on effective/rapid containment.
- Good understanding of AI and means it can optimize/build quality in Security Operations.
- Strong analytical thinking and problem-solving skills.
- Good communication skills and ability to collaborate across technical teams.
- Flexibility and perseverance needed to navigate through internal/external organization
- Self-organized, eager to continuously learn and to keep up to date with trends in information security.
- Proficient in English.
- Graduating from university in technical field: computer science, automated control, electronics, telecommunications, cybernetics or related.
- Minimum 3 years working experience in security engineering domains.
- Previous experience in security platform administration is a plus.
- International certifications in information systems and/or security is a plus (vendor related or international organizations – CCNA, CISSP, CCSP, CEH etc.).
- Previous experience in Banking or in other financial services is a plus.
If you want to find out what other jobs we still have available, like Life at BT or what #Culture BT is, you can also access the Bank's career website: https://cariere.bancatransilvania.ro/
Ready to venture into this technological journey?