View all jobs

IT Security Monitoring Expert - September 2027

  • remote, remote

For one of our clients in the energy industry, we are looking for a freelance IT Security Monitoring Expert

Project name: Defending the Castle
 
Project description: “Defending the Castle” is the short-term and immediate phase of the client’s AI threat resilience response. The purpose is to buy time by increasing detection, response, containment and recovery readiness while a broader Phase 2 plan is prepared for the rest of the Business IT units.

Tasks:
  • Conceptual development and structured implementation of the short-term security monitoring strategy for “Defending the Castle”, focused on detecting AI-augmented threats across hybrid Azure and on-premise environments.
  • Translation of frontier-model driven threat scenarios into actionable detection logic, monitoring requirements, telemetry gaps, alerting rules and escalation criteria.
  • Provision of technical consultation and recommendations to SOC, Cyber Defense Center, incident response, threat intelligence, cloud, identity, endpoint and platform teams to improve detection coverage at machine-speed threat tempo.
  • Definition and validation of monitoring use cases for lateral movement, privilege escalation, identity abuse, cloud control-plane abuse, data staging, exfiltration and persistence across Azure zones and on-premise networks.
  • Production of playbooks, SOPs and tuning guidance that allow monitoring teams to detect, triage and escalate AI-assisted attacks with reduced ambiguity and consistent quality.
  • Establishment and technical definition of measurable detection coverage, alert quality and response-readiness metrics to support Q1 2027 completion and readiness for Phase 2.
  • Creation of immediate visibility into the most likely AI-accelerated attack paths affecting identity, cloud, endpoint, network and privileged access layers.
  • Optimization and technical evaluation of telemetry, correlation, enrichment, and alert prioritization for detection efficiency.
  • Provision of practical runbooks for SOC and monitoring teams that can be executed under pressure without relying on individual tribal knowledge.
  • Conceptual strengthening and technical enhancement of early-warning capability before a broader business IT resilience programme is launched.
  • Technical peer review of detection logic across SOC, incident response and platform functions.
  • Execution and technical documentation of Purple-team exercises and tabletop scenarios, including simulated alert generation and escalation testing.
  • Compilation of an evidence pack containing detection catalog, data-source matrix, runbooks, tuning history and open risk register.
  • Preparation of documentation to facilitate operational sign-off from SOC lead, Cyber Defense lead and relevant Azure/on-prem service owners.
  • Identification and technical gap analysis of existing processes (too slow, fragmented, undocumented or dependent on informal knowledge) to document optimization potential.
  • Transformation of risk evaluations into executable playbooks, technical control frameworks, test protocols, backlog items and management evidence.
  • Provision of a structured handover of a Phase 2 backlog and recommendations for the broader Business IT resilience plan after Q1 2027.
  • Creation of comprehensive documentation with all results regarding the above-mentioned tasks with subsequent handover to client for review and approval for further usage.

Required skills:
  • Minimum 8 years in cyber defense operations, SOC engineering, detection engineering, threat hunting or security monitoring.
  • Strong expertise in SIEM, XDR, EDR, Microsoft Sentinel or equivalent platforms, KQL/SPL-style query languages and cloud/security telemetry.
  • Good understanding of Azure security monitoring, Entra ID, hybrid identity, endpoint telemetry, network logs, MITRE ATT&CK and attack-chain analysis.
  • Experience creating operational runbooks, alert tuning processes and SOC quality metrics.
  • Relevant certifications such as GCIA, GCIH, GCDA, SC-200, AZ-500, CISSP or equivalent are beneficial

Start: ASAP
Duration: till end of March 2027
Capacity: 40h/week
Location: Remote