0SOC Analyst - Focus on Incident Triage, Analysis and Response (m/f/d)
EDEKA IT Stiftung & Co. OHG | Germany | 32xxx Minden | Permanent position | Full time / Home office | Published since: 15.07.2026 on stepstone.de

SOC Analyst - Focus on Incident Triage, Analysis and Response (m/f/d)

Branch: Computer science, informati... Branch: Computer science, information and communication technology


We at EDEKA IT are the heart of digital change in the EDEKA association. As a powerful team, we develop IT strategies, infrastructures and services for all trading areas of the EDEKA association throughout Germany. We bundle our competencies to develop and implement innovative solutions. That's how we drive the trade of tomorrow - maybe soon together with you? In your role as SOC Analyst - Focus on Incident Triage, Analysis and Response (m/w/d) at Minden site, you can make your personal contribution to our goals. .

Your tasks • Your profile • What we offer

You monitor, evaluate and edit Security-Alerts (Splunk ES, CrowdStrike Falcon) in the 1st and 2nd levels. You analyze security incidents deeply to determine their scope (scope), the cause (root Cause), affected systems/accounts as well as the tactics of the attackers (TTP reconstruction). You initiate immediate countermeasures (Containment/Eradication), for example the isolation of hosts, the blocking of accounts or the setting up of blockings. You coordinate the processes and communicate directly with the stakeholders of the subsidiaries during ongoing incidents. You document and prepare incidents to define Lessons Learned and create management reports. You develop and care for SOPs, Runbooks, as well as escalation processes for fast immediate action. You develop our SIEM apps (Dashboards, Notable-Handling) based on your operational feedback from the daily business. You design and optimize SOAR playbooks to efficiently automate recurring response steps. You participate in the standby service (readiness to leave the core working time). You give structured feedback to the teams for Cyber Threat Intelligence (CTI) and SOC engineering to continuously improve the recognition quality (edge positive rate, coverage gaps).

You have successfully completed your studies or training with IT cover or have an equivalent qualification. A certification as SOC Analyst (level 1 or level 2) is very welcome. You own well-founded splunk knowledge especially in SPL, Splunk ES, Notable Handling and in dealing with Data Models and are experienced in SOAR automation, preferably in playbook development with Splunk SOAR. You bring practical experience with EDR platforms, ideally with CrowdStrike Falcon. You master scripting in Python, Bash and/or PowerShell to automate processes and efficiently integrate tools. You understand modern attack techniques and TTPs and are ideally suited to the MITRE ATT&CK framework. You are analytic and hypothesis-driven incident investigations. You also communicate strongly and sovereign under time pressure to ensure coordination with stakeholders. You know yourself in Windows and Linux system administration as well as Active Directory and Entra ID. You bring a high process affinity to continuously develop SOPs and Playbooks. You have fluent German language skills in word and font (CEFR level C1 or higher)

Work-Life-Balance: Benefit from 30 days of vacation and the opportunity to participate in mobile work (3 days office, 2 days home office). Influence: You shape the IT of the market leader in food retail in Germany. Financial incentive & other offers: Look forward to an attractive salary, asset-effective services, free salary account as well as other benefits & offers. General development (scientific & personal): We expect you to receive various training opportunities such as e.g. digital learning platforms and the possibility to participate in specialist conferences. Operational health management: Our health management takes care of your well-being in the workplace and beyond. Culture & cooperation: We offer you an optimal start in our company and place a lot of emphasis on good onboarding so that you can start right through and shape through our different communities and networks from the start. .

Location

ava EDEKA IT Stiftung & Co. OHG
Nürnberger Straße 63, 32427  Minden
Germany

The text of this ad was translated from German into English using an automatic translation system and may contain semantic and lexical errors. Therefore, it should be used for introductory purposes only. For more detailed information, see the original text of the ad at the link below.

For more information read the original ad

Permanent link to this ad

Ad Id