Founded in 1999 in Vienna, the Qualysoft Group is a manufacturer-independent IT consulting and services company, which successfully provides support for its international customers with the aim of boosting their competitiveness and economic efficiency through innovative IT solutions.
Its focus is on financial services providers, telecommunications companies, the automotive industry and energy service providers. Over 400 employees in 6 subsidiaries work together to ensure state of the art solutions for our clients.
We are looking for new colleagues in Qualysoft teams for diverse projects providing continuous learning opportunities. Our common goal is to provide honesty, development and a stable background while getting to know the latest technologies. We are waiting for your application for the position below!
Responsibilities:
Design and implement automated security workflows that connect tools across detection, response, and remediation pipelines.
Build integrations between SIEM/SOAR platforms, case management systems (e.g., ServiceNow, Jira, etc.), and internal APIs to enable automated ticketing, enrichment, and escalation.
Engineer SOAR playbooks to automate repetitive SOC tasks (e.g., IOC lookups, containment, notifications).
Integrate external threat feeds and CVE databases with internal asset inventories to support proactive vulnerability detection and patch prioritization.
Improve existing scripts, enrichment logic, and event correlation rules to reduce false positives and increase automation coverage.
Support the development of monitoring infrastructure (e.g., Fluentd, OpenTelemetry pipelines) with a security context.
Collaborate with DevOps, system owners, and analysts to ensure tooling is effective, resilient, and context-aware.
Ensure all automation aligns with internal policy and frameworks such as IT-Grundschutz, ISO 27001:2022, and C5:2022.
Provide engineering support during security incidents to build ad hoc response tooling or log aggregations and act as Tier 2 support for Cyber Security Analysts, including support of on-call duties, where necessary.
Ensure accuracy and continual improvement of related documentation, where applicable.
Requirements:
Bachelor's degree in Cybersecurity, Computer Engineering, or related technical field; equivalent experience also accepted.
Strong development/scripting experience with Python, Go, or Bash.
Experience designing and maintaining integrations between security platforms (SIEM, SOAR, threat intelligence platforms, ticketing systems).
Familiarity with SOAR tools such as Cortex XSOAR, Splunk SOAR, Tines, TheHive/Cortex, or similar.
Experience with cloud-native environments (e.g., Azure, AWS, or GCP), including APIs and identity models.
Strong knowledge of containerized environments (e.g., Docker, Kubernetes) and securing them.
Understanding of vulnerability management processes, CVE/CVSS standards, and real-world patching challenges.
Ability to build RESTful API integrations and data pipelines for security use cases.
3–5 years in a cyber security engineering or DevSecOps role.
Experience working in or supporting a SOC.
Familiarity with infrastructure-as-code (e.g., Terraform), GitOps pipelines, and securing CI/CD workflows.
Exposure to regulated environments (IT-Grundschutz, C5, ISO 27001, PCI-DSS, TISAX, KRITIS, etc.).
Why we think you will love working here:
With us you count as a person, our doors are always open.
We live the Qualysoft Team Spirit and stand for transparency!
Fresh wind and new ideas are welcome, because standstill is a foreign word at Qualysoft.