Point your AI agent at freehire and let it find you a job.

Get the CLI →

Security Operation Center L2 Engineer

NewBe an early applicant

⭐️ CoreStar is a dynamic technology company supporting partners in heavy-load industries with high-performance solutions. Our expert teams bring a startup-driven mindset, focusing on innovation, collaboration, and efficiency in every project. At CoreStar, you’ll have the opportunity to grow your skills, tackle exciting challenges, and directly contribute to impactful products.


⭐️ About the Role


We are seeking an experienced L2 SOC Engineer to strengthen our Security Operations Center. This role goes beyond day-to-day alert triage, for you will be a technical backbone of the SOC, responsible for onboarding and tuning log sources into SIEM, designing and improving SOC detection and response processes, and leading incident response for escalated security events. You'll work closely with IT/infrastructure, Security teams, and NOC to ensure the SOC has the visibility and processes it needs to detect and respond to threats effectively.


📌 Key Responsibilities:


Log Source Onboarding & Data Engineering

  • Own the end-to-end onboarding of new log sources into SIEM, including parsing, field extraction, normalisation, and enrichment
  • Design and maintain log pipelines, parsing rules, and data mappings to ensure high-quality, actionable telemetry
  • Build and maintain SIEM dashboards, alerts, and detection rules (e.g., SIEM Alerts, TCO optimisation, Data Flow rules)
  • Continuously assess log coverage gaps across the environment (endpoint, network, cloud, identity, application) and drive onboarding roadmaps
  • Optimise log volume, retention, and cost management within SIEM (TCO tiers, quota management)
  • Validate data integrity and troubleshoot ingestion issues, parsing failures, or delayed telemetry


SOC Process Design & Improvement

  • Design, document, and continuously improve SOC operating procedures, escalation matrices, and playbooks
  • Develop and maintain detection use cases and correlation logic aligned to MITRE ATT&CK
  • Define and track SOC KPIs/metrics (MTTD, MTTR, alert-to-incident ratio, false positive rates)
  • Build standard operating procedures (SOPs) for L1 analysts and ensure consistent triage quality
  • Support shift handover processes, escalation workflows, and quality assurance reviews of L1 work


Incident Response

  • Act as the primary escalation point for incidents
  • Lead investigation, containment, eradication, and recovery activities for security incidents
  • Perform log correlation, timeline reconstruction, and root cause analysis using SIEM and supporting tools
  • Coordinate with IT, DevOps, NOC, and business stakeholders during active incidents
  • Author detailed incident reports, post-incident reviews (lessons learned), and drive remediation tracking
  • Contribute to and maintain the organisation's Incident Response Plan (IRP)


📌 Required Qualifications

  • 3-5+ years of experience in a SOC/ security operations role, with demonstrated progression to L2 or equivalent
  • Strong experience with AI usage for SOC automation and detection.
  • Hands on expertise with SIEM (such as Splunk, Sentinel, QRadar, Elastic, Datadog) — SIEM experience strongly preferred.
  • Proven experience onboarding diverse log sources (firewalls, EDR, cloud platforms, identity providers, network devices, applications) into a SIEM/observability platform
  • Solid understanding of incident response frameworks (e.g., NIST 800-61, SANS IR) and hands-on IR experience
  • Strong knowledge of MITRE ATT&CK, common attack techniques, and detection engineering concepts
  • Experience writing/tuning detection rules, correlation logic, and reducing false positives
  • Familiarity with cloud environments (AWS/Azure/GCP) and cloud-native logging
  • Scripting/query skills (e.g., DataPrime/Lucene query syntax in SIEM, Python, or similar) for automation and analysis
  • Excellent documentation skills to design clear SOC processes, playbooks, and incident reports
  • Strong communication skills; comfortable presenting findings to technical and non-technical stakeholders


📌 Benefits:

🏝 24 working days of paid annual leave

🤝 6 days of paid sick leave

🖊 Official employment

📄 Medical insurance

☕️ Coffee zone with fruit & snacks available in the office

🥗 Corporate Lunch provided by the company

💪 Gym and sports classes

🙌 Healthy and friendly work atmosphere

📚 Greek and English language classes (partially covered)


Join us and be one of the Core Stars! ⭐

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available