SIEM - SOAR DevOps Engineer

Sista ansökningsdag: 9 juli
Arbetsort: Stockholm
Publicerat: För 12 timmar sedan
Kategorier: Data & IT Teknik & Ingenjör
Join our Team
About the Opportunity
We are seeking an experienced SIEM/SOAR DevOps Engineer to join the Cyber Defense Center (CDC) within Group Security at Ericsson.
The Cyber Defense Center plays a critical role in protecting Ericsson from cyber threats posed by external adversaries. Our mission is to stay ahead of sophisticated threat actors by anticipating their tactics, obstructing their operations, and eliminating any presence they may establish within our environment. We focus on the most advanced and potentially damaging cyber threats facing Ericsson. To accomplish this, the CDC is composed of several specialized teams, including:
• The Security Operations Center (SOC)
• EriCERT (Incident Response & Threat Hunting)
• Threat Intelligence
• Red Team
• Process & Governance
• AI
• Cyber Defense IT Operations
As an experienced SIEM/SOAR DevOps Engineer, you will be part of the Cyber Defense IT Operations team, with a primary focus on the development and operation of our SIEM and SOAR platforms. In addition to this core responsibility, you will support a range of other IT operations activities as required.
What You Will Do
• Design, develop, and operate our SIEM and SOAR platforms (e.g., Palo Alto Cortex XSOAR).
• Ensure robust, scalable, and secure integrations across a wide range of cloud-based security services (e.g., Microsoft Sentinel, Microsoft Defender Portal, AWS GuardDuty, GCP SCC).
• Support the onboarding, parsing, and enrichment of log sources using tools such as Fluentbit, Logstash, OpenSearch, and Kafka.
• Drive automation and orchestration initiatives to improve incident response and operational efficiency.
• Collaborate closely with CDC teams such as SOC, Threat Intelligence, AI, and EriCERT to strengthen detection and response capabilities.
• Work with infrastructure-as-code deployments using Terraform and Ansible.
• Take ownership of relevant documentation, playbooks, and operational procedures.
• Engage in ongoing optimization and performance tuning of the security operations stack.
• Perform additional IT operations tasks as required by the Cyber Defense IT Operations team.
You will bring
The Skills You Bring
• Strong programming skills in Python
• Advanced knowledge and hands-on experience with Linux systems
• Experience working with Cloud Security SaaS services
Meritorious Qualifications:
• Familiarity with SOAR platforms, preferably Palo Alto Cortex XSOAR
• Experience in application operations, DevOps pipelines, & infrastructure automation
• Hands-on experience with cloud environments (Azure, AWS, GCP) and cloud-native security tools such as Sentinel, Defender, GuardDuty, GCP SCC
• Experience with log management and parsing tools (e.g., Fluentbit, Logstash, Kafka)
• Experience with OpenSearch/Elasticsearch
Soft Skills:
• A team player with strong collaboration skills
• Proactive and self-driven, with a continuous learning mindset
• Ability to adapt quickly to new technologies and changing environments
• Strong documentation skills and attention to detail
• Ability to see the bigger picture and think strategically
• Documentation skills and positive can-do attitude
• Proficiency in English, both verbal and written
Why join Ericsson?
At Ericsson, you´ll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what´s possible. To build solutions never seen before to some of the world’s toughest problems. You´ll be challenged, but you won’t be alone. You´ll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?
Click Here to find all you need to know about what our typical hiring process looks like.
Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.
Primary country and city: Sweden (SE) || Stockholm
Req ID: 767688
Senaste jobben från Ericsson
-
Developer(5)
För 12 timmar sedan
-
System Architect ASIC
För 12 timmar sedan
-
Developer
För 12 timmar sedan
-
Master Developer AI in PHY
För 12 timmar sedan
-
Baseband SW Developer
För 12 timmar sedan
-
SIEM - SOAR DevOps Engineer
För 12 timmar sedan
-
Data and AI Foundation Developer
För 12 timmar sedan
-
Researcher Standardization
För 13 timmar sedan
-
Solution PM
För 13 timmar sedan
-
Data Analytics & RRM
5 juni
-
Master Thesis Scholar program at Ericsson Research, Gothenburg
5 juni
-
RAN System Developer
5 juni
-
ASIC SoC Verification Engineer
4 juni
-
LPP Developer
4 juni
-
Experienced Researcher - IC design
4 juni
-
Senior Specialist-Engineering Environment Architecture
4 juni
-
Senior Software Engineer
4 juni
-
Software Developer
3 juni
-
Senior Baseband Software Developer
3 juni
-
Senior ASIC IP Verification
3 juni
-
Hardware Systems Expert
3 juni
-
Security Specialist
3 juni
-
RAN Developer
3 juni
-
Silicon Design Data Scientist
3 juni
-
Silicon DevOps - Jenkins Engineer
3 juni
-
System modelling and design
3 juni
-
Electrical Building Practise Researcher
3 juni
-
Platform Engineer
2 juni
-
Java (JCAT) Developer
2 juni
-
Line Manager
2 juni
-
Enterprise IT Security Architect
30 maj
-
Trainee Patent Engineer-Attorney
30 maj
-
Radio Functional System Engineer
28 maj
-
Project Manager - Board Design
28 maj
-
Ran Digital Twin Researcher
28 maj
-
Senior ASIC Validation Engineer
28 maj
-
DevOps Engineer
28 maj
-
Arcitecture Evolution Program Manager
28 maj
-
Radio Spectrum Senior Researcher
27 maj
-
Radio Test Integration RF
27 maj
-
Baseband Software Tester
27 maj
-
Radio Solution Driver
23 maj
-
Data Leakage Prevention- Architect
23 maj
-
PA Designer
23 maj
-
Experienced Core Network Researcher
22 maj
-
Enterprise Solution Architect
22 maj
-
Engineering Manager - Silicon Design
21 maj
-
ASIC Architect
20 maj
-
PD Baseband Developer
20 maj
-
Head of Workplace Services Strategy and Partnership
19 maj