Cyber Security Engineer
- Salary
- €3.6K–€4.7K/mo
- Hiring from
- Latvia
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
Our client is looking for a Cyber Security Engineer to join its Security Operations Center (SOC) team in Riga.
In this role, you will help build, maintain, and improve the technical environment behind security monitoring and incident response. You will work with SOC platforms, cloud environments, integrations, and automation, while helping the team strengthen its ability to detect, investigate, and respond to cyber threats.
This is a hands-on role for someone who enjoys solving technical security challenges and improving how security operations work in practice.
What you will do:
Manage and implement technical customer onboarding and integrations with SOC platforms, including SIEM, Microsoft Azure, Defender, Splunk, and ITSM systems.
Configure, maintain, and continuously improve SOC security tools, monitoring platforms, and related cloud security services.
Work with SIEM/SOAR platforms (such as Sentinel and Splunk), endpoint protection, and threat intelligence integrations.
Develop and fine-tune detection rules and monitoring use cases, and onboard new log sources.
Support critical-severity incidents by providing technical input, assisting escalation decisions, and ensuring appropriate follow-up.
Participate in threat hunting, threat intelligence work, and security investigations as needed.
Build and maintain automations, integrations, and CI/CD pipelines that make detection and response faster and more efficient.
Contribute to the continuous improvement of SOC tools, detection logic, and operational processes.
Document technical solutions, configurations, and SOC procedures.
Work closely with security, IT, and other cross-functional teams to implement security controls and best practices.
What we are looking for:
Minimum 2-4 years of experience in cybersecurity or IT roles such as SOC Analyst, Security Engineer, System Administrator, Network Administrator, or similar.
Experience analyzing security events using log data from SIEM, SOAR, firewalls, intrusion detection systems, endpoint tools, and network monitoring platforms.
Hands-on experience with Microsoft Azure, Microsoft Entra ID (Azure AD), and cloud security concepts.
Experience developing and tuning detection rules, onboarding log sources, and supporting security monitoring use cases within SOC platforms.
Solid understanding of incident response and security monitoring workflows, including alert triage, investigation, and escalation.
Good knowledge of Windows and Linux administration and system hardening fundamentals.
Understanding of networking fundamentals, TCP/IP, authentication mechanisms (MFA, SSO), and enterprise security principles.
A proactive approach to staying current with cybersecurity threats, technologies, and best practices.
Very good English communication skills (minimum B2).
Nice to have:
Scripting or automation skills (PowerShell, Python, or Bash) and experience working with APIs.
University degree or ongoing studies in Cybersecurity, IT, Computer Science, Engineering, or a related field.
Certifications such as Microsoft AZ-500 or SC-200, CompTIA Security+ or CySA+, CCNA, Splunk, or other relevant cybersecurity certifications.
What we offer:
€3,600-€4,700 gross per month, depending on experience and expertise.
Hybrid work model with a comfortable office in central Riga; 2 days per week in the office.
Additional time off, including 4 extra vacation days and a birthday off.
Family-friendly workplace with a dedicated space for children.
Individual development plan and an annual budget for external training.
Comprehensive health insurance, including dental and sports coverage.
A trusting, supportive, multicultural team that welcomes initiative and new ideas.