Founded in 1999 in Vienna, the Qualysoft Group is a manufacturer-independent IT consulting and services company, which successfully provides support for its international customers with the aim of boosting their competitiveness and economic efficiency through innovative IT solutions.
Its focus is on financial services providers, telecommunications companies, the automotive industry and energy service providers. Over 400 employees in 6 subsidiaries work together to ensure state of the art solutions for our clients.
We are looking for new colleagues in Qualysoft teams for diverse projects providing continuous learning opportunities. Our common goal is to provide honesty, development and a stable background while getting to know the latest technologies. We are waiting for your application for the position below!
Position Overview
We are looking for a Security Consultant – AI-Driven Threat Management to join our cybersecurity team in Budapest. The role focuses on security monitoring, alert triage, threat detection, incident investigation and threat hunting across cloud and hybrid environments. The position operates at Tier 1–2 level, with close collaboration with internal stakeholders and escalation to Tier 3 / Incident Response teams when required. The role includes participation in a 24/7 on-call rotation
Key Responsibilities
Monitor and respond to security alerts in a 24/7 security operations environment, including participation in an on-call rotation
Perform initial security alert triage and validation using logs, telemetry and contextual information
Investigate security events in collaboration with internal stakeholders and system owners
Escalate confirmed or high-risk incidents to Tier 3 or Incident Response teams with detailed technical findings
Develop, tune and continuously improve detection rules, alert logic and correlation use cases based on real-world threats and the MITRE ATT&CK Framework
Support and co-lead security investigations, including identifying root causes, lateral movement and potential data exposure
Conduct threat hunting and purple teaming exercises to proactively identify novel threats
Contribute to the development and continuous improvement of SOC playbooks, investigation runbooks and incident response procedures
Support the customization of security response strategies for cloud infrastructure environments, including SAP Cloud Infrastructure
Create and maintain security dashboards, metrics and KPIs to monitor SOC effectiveness and threat landscape trends
Participate in lessons-learned reviews and provide recommendations for improving security detection and response processes
Requirements
2–4 years of experience in a Security Operations Center (SOC) or cybersecurity operations role, preferably in cloud-based or hybrid environments
Hands-on experience with security monitoring and workload protection in public cloud environments such as Microsoft Azure, AWS or GCP
Practical experience with security alert triage, basic forensic analysis and incident response support
Experience investigating cloud-native security events, such as IAM misconfigurations, insecure storage, compromised credentials or unusual container activity
Hands-on experience with at least one SIEM platform, such as Splunk, ElasticSearch, OpenSearch or DataDog
Experience with log analysis and security monitoring tools, as well as familiarity with Threat Intelligence Platforms
Proven experience creating, maintaining or tuning detection rules and custom security alerts
Good understanding of cloud-native security principles, networking protocols, Linux internals and common security controls
Familiarity with Docker, Kubernetes and other container technologies
Knowledge of the MITRE ATT&CK Framework and NIST incident handling lifecycle
Basic understanding of malware behavior and security investigation techniques
Experience developing or using incident handling playbooks and security runbooks
Basic understanding of security within Infrastructure as Code (IaC) and static code analysis tools
Good scripting and automation skills in Python, PowerShell or Bash are an advantage
Bachelor’s degree in Computer Science, Information Security or a related technical field, or equivalent practical experience
Preferred Certifications
CompTIA Security+
GIAC GSEC / GCIH
EC-Council CEH
Microsoft SC-200
Why we think you will love working here:
With us you count as a person, our doors are always open.
We live the Qualysoft Team Spirit and stand for transparency!
Fresh wind and new ideas are welcome, because standstill is a foreign word at Qualysoft.