DevSecOps Engineer / Threat Hunter

Job type:Contract
Town/City:Berlin
Region:Brandenburg
Sector:Cyber Security
Client Company Type:In-House
Job ref:10786
Post Date:September 29, 2026

About the Role

DevSecOps Engineer / Threat Hunter

The Opportunity

Most security roles make you choose. Build the platform, or hunt on it. This one gives you both.

You'll own a Google SecOps environment end to end, and you'll have the mandate to go looking for the activity nobody else has spotted. What you find won't sit in a report. It becomes detection logic that stops the next attempt.

The organisation is actively investing in its security operations. That means your work shapes how detection is done here, rather than simply maintaining what someone else built.

The Role

  • Own the Google SecOps platform end to end: onboard new data sources, configure parsers and data models, and close gaps in telemetry quality.
  • Turn your knowledge of adversary techniques into detection rules and use cases, reviewing them regularly to keep noise down.
  • Set the agenda for proactive threat hunting, building hypotheses and following suspicious activity wherever it leads across the estate.
  • Feed what you learn from every hunt back into the detection library.
  • Work alongside SOC colleagues to raise the maturity of detection and response across the organisation.

The split matters. Engineering time keeps the data trustworthy. Hunting time keeps you sharp. Each one makes the other better.

The Company

You'll join a well-established organisation that has made a deliberate decision to get ahead of attackers rather than react to them. This role sits at the centre of that effort.

The remit is practical and hands-on, within an existing security operations team. You'll have colleagues to work with, a platform you're trusted to run, and a clear line between your work and the organisation's defensive posture.

What You'll Need

  • Hands-on engineering experience with Google SecOps (formerly Chronicle), including ingestion, parsing and data normalisation.
  • Hypothesis-driven threat hunting experience, grounded in a detailed understanding of adversary behaviour and using MITRE ATT&CK as a working reference.
  • The ability to assess log sources and telemetry for completeness and reliability.
  • A practical approach to writing and tuning detection logic that keeps alert volumes meaningful without leaving blind spots.

How to Apply

If this sounds like the role you've been waiting for, get in touch with the MAM Gruppe team for a confidential conversation.

Your CV doesn't need to be up to date. Send what you have, or just give us a call.

More Jobs from this Recruiter

Berlin, Brandenburg

DevSecOps Engineer / Threat Hunter

DevSecOps Engineer / Threat Hunter The Opportunity Most security roles make you choose. Build the platform, or hunt on it. This one gives you both. You'll own a Google SecOps environment end to end, and you'll have the mandate to go looking for the activity nobody else has spotted. What you find won't sit in a report. It becomes detection logic that stops the next attempt. The organisation is actively investing in its security operations. That means your work shapes how detection is done here, rather than simply maintaining what someone else built. The Role Own the Google SecOps platform end to end: onboard new data sources, configure parsers and data models, and close gaps in telemetry quality. Turn your knowledge of adversary techniques into detection rules and use cases, reviewing them regularly to keep noise down. Set the agenda for proactive threat hunting, building hypotheses and following suspicious activity wherever it leads across the estate. Feed what you learn from every hunt back into the detection library. Work alongside SOC colleagues to raise the maturity of detection and response across the organisation. The split matters. Engineering time keeps the data trustworthy. Hunting time keeps you sharp. Each one makes the other better. The Company You'll join a well-established organisation that has made a deliberate decision to get ahead of attackers rather than react to them. This role sits at the centre of that effort. The remit is practical and hands-on, within an existing security operations team. You'll have colleagues to work with, a platform you're trusted to run, and a clear line between your work and the organisation's defensive posture. What You'll Need Hands-on engineering experience with Google SecOps (formerly Chronicle), including ingestion, parsing and data normalisation. Hypothesis-driven threat hunting experience, grounded in a detailed understanding of adversary behaviour and using MITRE ATT&CK as a working reference. The ability to assess log sources and telemetry for completeness and reliability. A practical approach to writing and tuning detection logic that keeps alert volumes meaningful without leaving blind spots. How to Apply If this sounds like the role you've been waiting for, get in touch with the MAM Gruppe team for a confidential conversation. Your CV doesn't need to be up to date. Send what you have, or just give us a call.
Learn More

Latest Blogs

View all blogs