Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education & Training jobs
  • Remote Healthcare & Nursing jobs
  • Remote Construction & Built Environment jobs
  • Remote Skilled Trades & Field Service jobs
  • Remote Research & Science jobs
  • Remote Real Estate & Property jobs
  • Remote Retail & Merchandising jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTermsLogos provided by Logo.dev

Contact mahmoud@relomote.com · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Cegeka logo

Security Engineer

Cegeka
Posted 5 hours ago
🇷🇴Romania🏠Remote📁Engineering & Development
Is this job info correct?

Our mission is to help people integrate technology into everyday life and to enable innovation through technology. We offer software development and infrastructure solutions, with advanced competences in Blockchain, Artificial Intelligence and Machine Learning. All our offices (in Western Europe or nearshore, in CEE) are located within the boundaries of the European Union. We believe working in close cooperation with our clients and employees is the key to success; this means we offer people the best working environment in order to achieve the best results. We love entrepreneurial spirits and encourage people around us to be proactive and make the best decisions not only for business, but for their own personal development. Our nearshore Romanian offices are in Bucharest (Victoriei Square) and Iasi (Palace) and, with over 9000 team members at group level, we make sure we are always close to our customers.


Role Overview:


The Security Engineer - Detection & Response is responsible for building,

maintaining, and continuously improving the technical capabilities that support

Cyber Detection & Response.


The role ensures strong detection coverage, reliable operational pipelines, and

effective engineering support for both security monitoring and incident response.


The role focuses on implementing prioritized detection use cases end to end,

including observability, telemetry pipelines, correlation, enrichment, automation,

and the integrations required to operationalize them for SOC and CSIRT teams.


It also provides hands-on engineering support for response automation and

orchestration, helping improve the speed, quality, and efficiency of investigative

and response workflows.


Key Responsibilities:


1. Detection Engineering

  • Design, build, and maintain high-fidelity detections across SIEM, XDR, EDR, identity, network, cloud, and data security telemetry sources.
  • Correlate security telemetry with broader datasets to identify advanced threat actor tactics, techniques, and procedures (TTPs).
  • Author, optimize, and maintain detection logic, including SQL-based and platform-native detection rules.
  • Tune alerts continuously to reduce false positives and improve the signal-to-noise ratio for the 24/7 SOC.
  • Replicate and adapt detection use cases across multiple business units, brands, and security tool tenants.


2. Security Automation and Orchestration

  • Build, maintain, and troubleshoot Tines workflows and orchestrated playbooks to automate alert triage, enrichment, escalation, containment, and closure.
  • Develop and maintain ChatOps and SecBot-driven response automations integrated with collaboration platforms such as Slack.
  • Improve and support automation that enhances incident response efficiency, including enrichment workflows, notification pipelines, and dashboard reliability.
  • Explore and prototype AI-assisted security workflows, such as automated malware analysis, alert correlation, and investigation support.


3. Telemetry Onboarding and Data Pipeline Engineering

  • Engineer and maintain security data pipelines to ensure events are enriched with relevant context such as identity, asset, and geolocation data before reaching incident response teams.
  • Onboard new telemetry and log sources into the detection pipeline.
  • Validate log quality, perform cleanup where needed, and ensure schema alignment with detection and analytics requirements.
  • Expand telemetry coverage across new brands, business units, and environments.


4. Incident Response Engineering Support

  • Provide engineering support during security incidents, including automation of containment actions, escalation routing, and forensic data enrichment.
  • Build and operate technical workflows that improve incident handling speed, consistency, and accuracy.


5. Platform Reliability and Operational Readiness

  • Ensure the availability, effectiveness, quality, and resilience of SOC and CSIRT tooling, pipelines, and detection engineering capabilities.
  • Proactively identify, troubleshoot, and urgently resolve issues affecting detections, alerting, integrations, automations, enrichments, dashboards, and Tines applications.
  • Maintain the health and continuity of the SOC and CSIRT operational pipeline.


6. Monitoring and Process Improvement

  • Continuously improve security monitoring operations, including alert filtering, notification clustering, queue handling, and escalation logic.
  • Identify and implement engineering solutions that improve SOC and incident response efficiency, including automation of manual activities and system tuning.
  • Improve support for after-hours, holiday, and high-volume monitoring scenarios.
  • Design and implement recurring operational and stakeholder reporting.


7. Documentation and Continuous Improvement

  • Create and maintain technical documentation, runbooks, and operational procedures related to detection engineering and security operations.
  • Contribute to technology evaluations, tooling improvements, and core infrastructure modernization initiatives.
  • Present innovation initiatives and technical improvements to relevant security stakeholders.


Requirements


Technical Skills & Experience

  • Proven experience in detection engineering, with hands-on work designing and maintaining detections across SIEM, XDR, EDR, identity, network, cloud, and data security telemetry sources
  • Strong knowledge of threat actor TTPs and experience correlating security telemetry across multiple data sources to identify advanced threats
  • Proficiency writing and optimizing detection logic, including SQL-based queries and platform-native detection rules
  • Experience tuning alerts and reducing false positives in a 24/7 SOC environment
  • Experience replicating/adapting detection use cases across multiple business units, brands, or tool tenants

Automation & Orchestration

  • Hands-on experience with Tines (or similar SOAR platforms) building and troubleshooting workflows/playbooks
  • Experience with ChatOps/bot-driven response automation integrated with Slack or similar collaboration tools
  • Experience developing automation for alert triage, enrichment, escalation, containment, and case closure
  • Familiarity with AI-assisted security workflows (e.g., automated malware analysis, alert correlation, investigation support) is a plus

Data Pipeline & Telemetry Engineering

  • Experience engineering and maintaining security data pipelines, including enrichment with identity, asset, and geolocation context
  • Experience onboarding new log/telemetry sources into detection pipelines
  • Strong understanding of log quality validation, schema alignment, and data cleanup practices
  • Experience scaling telemetry coverage across new environments, brands, or business units

Incident Response Support

  • Experience providing engineering support during live security incidents
  • Ability to build/operate workflows that improve IR speed, consistency, and accuracy, including automated containment and escalation routing

Platform Reliability & Operations

  • Experience ensuring uptime, resilience, and reliability of SOC/CSIRT tooling, pipelines, and detection capabilities
  • Strong troubleshooting skills; ability to proactively identify and urgently resolve issues in detections, integrations, automations, and dashboards
  • Experience maintaining operational continuity of SOC/CSIRT pipelines

Process Improvement & Reporting

  • Experience improving monitoring processes: alert filtering, notification clustering, queue management, escalation logic
  • Track record of identifying and implementing engineering solutions that increase SOC/IR efficiency
  • Experience designing recurring operational/stakeholder reports
  • Experience supporting after-hours, holiday, or high-volume monitoring scenarios

Documentation & Collaboration

  • Strong technical documentation skills (runbooks, operational procedures)
  • Experience contributing to tooling evaluations and infrastructure modernization initiatives
  • Ability to present technical improvements/innovation initiatives to security stakeholders
  • Strong cross-functional collaboration skills (SOC, CSIRT, engineering teams)


Once on board we offer various programs and benefits:


  • 22 annual vacation days, 3 sick days that are not carried to the next year (no medical certificate required)
  • A seniority day is added every 3 years in the company
  • Floating days - free day for every public holiday that falls on the weekend, with the exception of holidays which always fall during the weekend
  • Annual Company Bonus prorated according to the number of worked months in a year
  • Private medical insurance
  • Access to an online benefit platform, with a monthly allowance of 690 RON, which you can choose to invest in different wellbeing, financial, or retail packages
  • Financial support for the birth of your child or unhappy events
  • A work culture based on cooperation and development - customized learning paths through external providers as well as special development programs.
  • We offer remote work flexibility, driven by smart working principles and aligned with team goals and values
  • Wellbeing initiatives to encourage a healthy work life balance through webinars, specialized sessions and internal programs, per our colleagues’ input


Similar jobs

Similar jobs

Veoneer Romania Safety Systems logo

IT Security Engineer

Veoneer Romania Safety Systems

🇷🇴RomaniaYesterday
S&

Application Security Engineer

Script & Dot

🇷🇴Romania6 days ago
emagine logo

Test Security/Penetration Test Engineer

emagine

🇷🇴Romania1 weeks ago
UN

Senior DevSecOps Engineer - Security Automation

Undelucram.ro

🇷🇴Romania1 weeks ago
Digital Zone logo

Staff Security Engineer

Digital Zone

🌍Egypt, Poland, Romania, United Arab Emirates2 weeks ago
meteocontrol GmbH logo

OT Security Engineer (all genders)

meteocontrol GmbH

🇷🇴Romania2 weeks ago