CrawlJobs Logo

SOC Cyber Threat Expert

Türkiye, Ankara · Job Posted June 15, 2026
Apply Position
Job Link Share

Job Description

At Vodafone, we’re not just shaping the future of connectivity for our customers – we’re shaping the future for everyone who joins our team. When you work with us, you’re part of a global mission to connect people, solve complex challenges, and create a sustainable and more inclusive world. If you want to grow your career whilst finding the perfect balance between work and life, Vodafone offers the opportunities to help you belong and make a real impact.

Job Responsibility

  • Coding Experience in Scripting & programming languages (such as Java, Bash, Python, PowerShell, etc.) to use these skills to aid in responding to incidents involving Windows, Linux, and Mac hosts, as well as automate common analytical processes to reduce analyst time and avoid repetitive incident response tasks
  • Making assessments on Information Security processes and taking responsibility of implementing improvements on related systems
  • Deploy, configure, and maintain security technologies, including, EDR, XDR, SOAR, SIEM, solutions to assess each of the cybersecurity technology’s responses
  • Develop open-source and vendor based threat detection scenarios
  • Develop tooling for Detection Development Life-Cycle
  • Research on new threat hunting methodologies, tools, and technologies
  • Onboard and maintain detection and hunting products (SIEM, EDR, etc.)
  • Manage and maintain internal SOC technologies and processes
  • Effectively use threat intelligence services and malware sandboxes for hunting new malware threats
  • Excellent written skills with demonstrated ability to write reports

Requirements

  • Bachelor’s Degree in engineering departments (preferably Electronics or Computer Engineering)
  • 5+ years of experience in performing hands-on security engineering, consulting, team management, penetration testing, and/or adversary simulation, red teaming exercises, vulnerability assessments in complex operational ICT environments
  • Familiarity with industry standards like OWASP TOP10, CVSS, CIS, NIST etc.
  • CISSP, CISM, OSCP, CEH level is expected
  • Experienced in SIEM products (QRadar, FortiSIEM Splunk, Logsign etc.) and SOAR products
  • Experience working with Threat modeling (e.g., STRIDE, PASTA, FAIR, Security Cards), operational threat intelligence, and attack framework standards (e.g., MITRE ATT&CK) with a good understanding of the Cyber Kill Chain and pervasive threat attack methods and remediation
  • Experience working in an industry standard Security Operations Center or similar environment providing incident handling and response, intrusion detection, analysis, cyber threat intelligence, threat determination, and mitigations processing and tracking, working with several network and system security technologies to include Elasticsearch, data analytics platforms, endpoint tools, network technologies, and SIEMs
  • Experience developing detection logic for enterprise SIEM systems and with exploitation techniques and use case development
  • Experience in the detection and response to malicious activity using log data and alerts from cybersecurity solutions, systems, and network devices
  • Experience extracting and analyzing forensic artifacts across Windows, Mac, and Linux operating systems
  • Experience of incident response processes, and threat intelligence cycles, including understanding of IP network traffic, security vulnerabilities, different exploitation techniques, and malware behaviors (including communications protocols)
  • Understanding of Amazon Web Services cloud environments and their security controls, microservices architectures & distributed Platforms especially in the SaaS businesses, global frameworks and standards like NIST, ISO 27001/27002/27017/ 27018, GDPR, etc.

Nice to have

Experience in Scrum is a plus

What we offer

  • Vflexy: Flexible Benefits Program
  • Hybrid working kit
  • Ergonomic kit allowance
  • Digital meal voucher
  • Flexible transportation allowance
  • Employee assistance hotline & counselling
  • Comprehensive and flexible private health insurance
  • Discounted price deals for wide range of products & services

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

SOC Cyber Threat Expert

8 matching positions

Senior Cybersecurity Expert (Threat Intelligence)

At Bosch, we shape the future by inventing high-quality technologies and service...
Location
Location
Poland , Warszawa
Salary
Salary:
Not provided
https://www.bosch.pl/ Logo
Robert Bosch Sp. z o.o.
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in Computer Science, Cybersecurity, or a related field
  • Several years of experience in a technical cybersecurity role (e.g., CTI, SOC, Threat Hunting, Incident Response, DFIR)
  • Proven expertise in tracking and analyzing adversarial behavior, with strong knowledge of the cyber kill chain and MITRE ATT&CK framework
  • Ability to work methodically and independently while being an effective and reliable team player in a distributed team
  • Excellent communication skills with the ability to translate complex technical findings for diverse stakeholders
  • Strong scripting and tool development experience (Python, APIs, Git, Docker)
  • Fluent in English
  • German is a plus
Job Responsibility
Job Responsibility
  • Identify, analyze, and track threat actor TTPs and IOCs using threat prioritization frameworks and threat landscape monitoring
  • Investigate complex threat data to provide situational awareness, quantify trends, support ongoing investigations, and strengthen detection and response capabilities
  • Conduct in-depth technical analysis (searching, pivoting, enrichment) to support Threat Hunting and identify potential intrusions in Bosch networks and systems
  • Collaborate closely with cross-functional teams including Incident Response and Detection Engineering to integrate intelligence into detection and response workflows
  • Produce and deliver high-quality intelligence reports, briefings, and presentations tailored to technical, business, and executive audiences
  • Respond to Requests for Information (RFIs) and brief stakeholders on emerging campaigns and significant incidents
  • Develop and improve internal tools for threat analysis and monitoring (using Python, REST APIs, Git, Docker)
What we offer
What we offer
  • Competitive salary + annual bonus
  • Hybrid work with flexible working hours
  • Referral Bonus Program
  • Copyright costs for IT employees
  • Private medical care and life insurance
  • Cafeteria System with multiple benefits (incl. MultiSport, shopping vouchers, cinema tickets, etc.)
  • Prepaid Lunch Card
  • Number of benefits for families (for instance summer camps for kids)
  • Non-working day on the 31st of December
  • Fulltime
Read More
Arrow Right

Cyber Threat Specialist

Critical role within the Cyber Threat Intelligence Team. As a Threat Specialist ...
Location
Location
Australia , Victoria
Salary
Salary:
Not provided
woolworths.com.au Logo
Woolworths Supermarkets
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 7+ years of tested cyber security experience within high-pressure environments, including SOC, NOC, and CIRT ecosystems
  • Expert-level mastery in network intrusion, detection, and response, with a current and sharp understanding of the modern threat landscape
  • Deep-seated intuition for malicious code, with the specialised skills required to understand the anatomy of an attack
  • Seamlessly applying the MITRE ATT&CK® framework and Cyber Kill Chain methodology to map adversary behavior and anticipate the 'next move'
  • Broad spectrum confidence across an array of security applications, ensuring the right tool is leveraged for the right threat at the right time
  • Advanced proficiency in Open Source Intelligence, turning public data into actionable defensive strategies
  • A rare ability to translate complex cyber risks into tangible business outcomes, ensuring security initiatives drive organisational value rather than just technical compliance
  • Comprehensive end-to-end exposure to Incident Response (IR), from initial triage through to post-mortem and long-term hardening
  • Equally effective as an individual contributor or a collaborative team player, maintaining peak performance in both autonomous and integrated environments
Job Responsibility
Job Responsibility
  • Maintain awareness of the cyber threat landscape by conducting research to contribute to formal threat reports and curate actionable intelligence
  • Triage, tune, and customise threat alerts while incorporating curated Indicators of Compromise (IOCs) into the existing threat framework
  • Identify and prioritise detection opportunities using SIEM and EDR tools, mapped against the Mitre ATT&CK framework for comprehensive coverage
  • Conduct threat hunting, trigger incident response workflows, and provide dedicated intelligence support during major security incidents
  • Proactively raise security risks and recommend appropriate controls to strengthen the organisation's defensive posture
  • Assist with the zero-day vulnerability process and ensure all technical documentation remains current and accurate
  • Drive continuous improvement by streamlining workflows through the strategic use of automation and advanced tooling
  • Fulltime
Read More
Arrow Right

SOC Lead - Cyber Security Operations

We are seeking an experienced SOC Lead to head Vodafone’s Security Operations Ce...
Location
Location
India , Bangalore
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 8+ years in security operations, including at least 4+ years in a SOC leadership or senior incident response role
  • Proven leader of 24x7 SOC teams, with a strong track record of improving MTTT/MTTR, triage quality, and operational performance
  • Technical authority in incident response, capable of leading complex investigations and making sound decisions under pressure
  • Highly experienced with SIEM platforms such as Splunk, Microsoft Sentinel, Google SecOps, ArcSight, or QRadar, and familiar with EDR/NDR technologies
  • Skilled in driving SOC automation, SOAR, and AI-enabled capabilities, with a clear understanding of governance and responsible use
  • Knowledgeable across network, endpoint, and cloud security, with a strong grasp of attacker techniques and the MITRE ATT&CK framework
  • Analytical decision-maker who balances risk, speed, and business impact in ambiguous situations
  • Passionate about developing people and building sustainable SOC capability for the future
  • Educated to degree level in Cyber Security, Computer Science, Information Technology, or a related discipline (or equivalent practical experience)
  • Holder of relevant certifications such as GIAC, CISSP, or vendor-specific SOC certifications
Job Responsibility
Job Responsibility
  • Lead and manage 24x7 SOC operations, ensuring consistent, high-quality alert monitoring, triage, and incident response across all markets
  • Own and drive SOC service performance against key KPIs including MTTT, MTTR, triage quality, and SLA adherence, delivering measurable improvements in detection quality, response speed, and efficiency
  • Oversee the full alert lifecycle, ensuring accurate investigation, containment, escalation, and high-quality incident reporting
  • Continuously enhance detection capabilities by improving SIEM use cases, alert logic, and playbooks, reducing false positives and increasing coverage across priority threat scenarios
  • Drive the adoption of automation, SOAR, and AI-assisted capabilities to improve speed, consistency, and scalability, with appropriate governance and human oversight
  • Lead SOC transformation initiatives focused on reducing alert fatigue, streamlining workflows, and improving analyst productivity
  • Build, coach, and develop a high-performing SOC team through structured capability development, performance management, and knowledge sharing
  • Act as the final escalation point for complex or high-risk incidents, applying expert judgement to validate and close cases
  • Deliver clear, data-driven SOC performance and incident reporting to senior leadership
  • Foster a culture of continuous improvement through post-incident reviews, detection retrospectives, and operational learning
What we offer
What we offer
  • The opportunity to lead a globally impactful SOC function within a recognised Cyber Defence Centre of Excellence
  • Exposure to large-scale, complex cyber defence operations across multiple international markets
  • The chance to shape and influence the future of SOC operations through automation and AI-driven transformation
  • A collaborative, inclusive environment that supports professional growth and continuous learning
  • The ability to work with advanced security technologies and experienced cyber defence professionals
  • Fulltime
Read More
Arrow Right

Cyber Security Expert

We are looking for a Cyber Security Expert who would be responsible for Evaluati...
Location
Location
India , Indore;Noida;Hyderabad
Salary
Salary:
Not provided
clear-trail.com Logo
ClearTrail
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Experience: 8 - 10 Years
  • Expertise on Evaluation, Implementation, and maintenance of SIEM/SOAR Solution
  • Security Incident Management policy and process implementation
  • Support cyber-security incident and operational reporting and metrics
  • Document security breaches and assess the damage they cause
  • Investigate security breaches and other cybersecurity incidents
  • Understand cyber-attack methods, perform analysis of security logs to detect/uncover and respond to cybersecurity threats and provide reports
  • Knowledge of vulnerability assessment, penetration testing, risk management, malware protection
  • Measures SOC performance metrics and communicates the value of security operations to business leaders
  • Contribute individually or as a team member to close all the Information Security Findings and ensure closure of all such internal/external audit observation perform tests and uncover network & system vulnerabilities
Job Responsibility
Job Responsibility
  • Evaluation, Implementation and maintenance of SIEM/SOAR Solution
Read More
Arrow Right

Senior Cyber Security Analyst – Incident Response & SOC

We don’t hang up the leash until the job is done. Senior Cyber Security Analyst ...
Location
Location
Salary
Salary:
Not provided
zeektek.com Logo
Zeektek
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Email security fundamentals (SPF, DKIM, DMARC)
  • Phishing and malware investigations
  • DFIR / forensic investigation skills
  • Deep incident response experience
  • Threat analysis across multiple log sources
  • Hands-on tooling knowledge (EDR, SIEM, malware analysis, endpoint/network forensics)
  • Strong troubleshooting and scenario-based thinking
  • Strong written and verbal communication skills
  • Working knowledge of Data Loss Prevention concepts/products, Data Encryption concepts, and endpoint management
  • Technical knowledge of common network protocols and design patterns including TCP/IP, HTTPS, FTP, SFTP, SSH, RDP, CIFS/SMB, NFS
Job Responsibility
Job Responsibility
  • Leading investigations and serving as a subject matter expert while correlating data across multiple log sources and systems
  • Continually improving cyber security procedures and documentation to enhance the security posture of the organization
  • Communicating with users, vendors, and other IT personnel on security-related issues, providing expert guidance and support
  • Staying up to date on evolving cyber threats, identifying their impact, and detecting them in our environment
  • Managing infrastructure security systems such as HIDS/NIDS, SIEM, NGAV, EDR, UBA, WAF, DLP, and vulnerability management tools to meet regulatory requirements
  • Collaborating with business groups to establish and maintain strong working relationships
What we offer
What we offer
  • Weekly Direct Deposit
  • 401K Matching
  • Competitive medical, dental and vision insurance
  • Consistent communication throughout your project
  • ZeekTek Referral Program
Read More
Arrow Right

Chief Information Security Officer

At Boeing, we innovate and collaborate to make the world a better place. We're c...
Location
Location
Australia , Brisbane
Salary
Salary:
Not provided
boeing.com Logo
Boeing
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Senior leadership experience in cyber and information security assurance ideally within Defence, national security, or critical infrastructure
  • Proven track record of building and leading successful teams
  • Deep knowledge of ISM, DSPF, DISP, and Defence accreditation processes, as well as familiarity with ISO 27001, NIST CSF, and NIST SP 800-171 frameworks
  • Demonstrated experience securing both IT and OT environments
  • Demonstrated experience leading regulatory compliance assessments/efforts pertaining to the ASD ISM and Essential Eight cybersecurity frameworks
  • Experience presenting complex security risks, strategies, and concepts in business terms to executive leadership and Board of Directors
Job Responsibility
Job Responsibility
  • Develop and implement a comprehensive information security and cyber defence strategy across Boeing Defence Australia and other regional subsidiaries, that integrates closely with the other non-cyber security domains
  • Advise the BDA CSO, executive leadership, and program directors on cyber risk management, threats, mitigation strategies and security investment
  • In close collaboration with Enterprise cybersecurity teams, ensure alignment between Australian requirements and Boeing global security standards
  • Ensure compliance with the ISM, DSPF, DISP, ASDEFCON security clauses, and Defence accreditation processes
  • Oversee IRAP assessments, system security plans, risk assessments, and continuous monitoring programs ensuring consistent implementation of ASD Essential Eight maturity targets
  • Lead cybersecurity for all IT and OT environments across Boeing Australia, including manufacturing systems, mission systems labs, sustainment facilities, and unmanned systems operations
  • Drive secure-by-design engineering for ICT, OT, cloud, and cross-domain solutions
  • Develop and oversee the Australian cyber defence capability, including SOC operations, threat intelligence, and incident response
  • Coordinate cyber incident management across BDA and other supported subsidiaries, in conjunction with local Boeing global IT and cyber teams, ensuring timely regulatory reporting is undertaken
  • Provide cybersecurity assurance for bids, platform upgrades, and sovereign capability programs
What we offer
What we offer
  • Competitive base pay and incentive programs
  • Industry-leading tuition assistance program pays your institution directly
  • Resources and opportunities to grow your career
  • Up to $10,000 match when you support your favorite nonprofit organizations
  • Fulltime
Read More
Arrow Right

Ss7 Monitoring Specialist

At Vodafone, we’re not just shaping the future of connectivity for our customers...
Location
Location
United Kingdom , Newbury
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Strong willingness to learn and adapt to new tools, technologies and emerging signalling threats in a fast moving security environment
  • Open minded, collaborative and comfortable working across technical and operational teams
  • Demonstrates resilience, curiosity and a positive attitude when operating in high pressure incident environments
  • Experience with telecommunications signalling protocols (SS7, Diameter, GTP‑C) or strong willingness to rapidly develop expertise in this area
  • Strong analytical capability across large signalling telemetry datasets to identify anomalies, abuse patterns and emerging threats
  • Experience working within an operational Cyber Defence or SOC environment, including incident triage and escalation
  • Hands‑on experience in security event analysis and incident response, particularly within network or telecoms contexts
  • Experience using security analytics and monitoring platforms such as Dynatrace, Splunk, Google SecOps and Tableau
  • Understanding of telemetry pipelines, log enrichment, and data quality considerations (e.g. Syslog, Cribl or similar)
  • Ability to communicate complex technical findings clearly to both technical and non technical stakeholders
Job Responsibility
Job Responsibility
  • Define, maintain and continuously improve Cyber Defence playbooks for SigFW related events
  • Develop clear and actionable incident reporting to support effective prioritisation, escalation and decision making
  • Support development and production integration of Signalling Intrusion Detection Systems (SigIDS)
  • Design and maintain operational dashboards and analytics to improve signalling security situational awareness
  • Perform continuous monitoring and triage of signalling security events in line with defined severity and escalation criteria
  • Lead the analysis of unusual signalling patterns, behaviours and anomalies within the network, identifying potential SS7/Diameter abuse and responding to threats before network impact occurs
  • Analyse known and emerging signalling attack techniques (e.g. interception, location tracking, routing manipulation, fraud enablement) and translate these into effective detection logic, analytics and investigative guidance
  • Maintain expert knowledge of SS7/Diameter abuse patterns and translate this into detection logic, alerts and investigative guidance
  • Feed lessons learned from incidents and intelligence back into preventative controls, dashboards and playbooks
  • Raise and manage incident and remediation tickets (e.g. Remedy)
What we offer
What we offer
  • Yearly bonus: 10%
  • Annual leave: 28 days + bank holidays + the opportunity to buy/sell/carry over 5 days/year
  • Charity days: 5 days/year
  • Maternity leave: 52 weeks: the first 13 weeks are fully paid, followed by 26 weeks of half pay
  • Private pension: You can contribute up to 5% of your basic pay with 2:1 matching from Vodafone up to 10%
  • Access to: private medical, private dental, free health assessments, share save scheme
  • Additional discounts: Vodafone retail, gym, cinema, cycle to work, season ticket loan
Read More
Arrow Right

Cyber Security Specialist

We are seeking a seasoned cyber security professional to lead the Vulnerability ...
Location
Location
India , Pune
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Possess over 10 years of IT experience with a strong focus on cyber security, vulnerability management, and remediation
  • Proficient in tools such as QualysGuard VMDR, WAS, and cloud scanning solutions
  • Skilled in web application penetration testing and knowledgeable in OWASP, Kali Linux, Burp Suite, CVE, SSL PKI, IAM, SIEM, and perimeter security
  • Experienced in managing large-scale vulnerability scanning operations and reporting
  • Strong stakeholder management and communication skills
  • Solid understanding of networking and cyber security policies, standards, and procedures
  • Advantageous if experienced in SOC, Endpoint Security, IAM, Information Protection, or the telecom industry
Job Responsibility
Job Responsibility
  • Lead the Vulnerability Management and Responsible Disclosure team to strengthen Vodafone’s cyber defence capabilities
  • Drive vulnerability management initiatives, ensuring timely identification, communication, and remediation of threats
  • Oversee penetration testing activities related to responsible disclosures and support incident response during crises
  • Research emerging threats, including zero-day vulnerabilities, and ensure targeted scans and mitigation actions
  • Champion continuous improvement through automation and cross-functional collaboration
  • Act as a technical expert in security scanning and penetration testing
  • Foster team development through individual growth plans and maintain high engagement levels
  • Contribute to administrative and delivery initiatives across domains
What we offer
What we offer
  • Opportunity to lead a high-impact domain within a global cyber security function
  • Exposure to cutting-edge vulnerability management tools and practices
  • Collaboration with international teams and stakeholders across Vodafone markets
  • A chance to influence Vodafone’s cyber risk strategy and operational resilience
  • A dynamic and inclusive work environment that values innovation and continuous improvement
Read More
Arrow Right