Senior Cybersecurity Researcher
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · DevOps · Datavetenskap
I korthet
Volvo Group is seeking a Senior Cybersecurity Researcher to join their Cyber Defense Center Engineering team in Göteborg, Sweden. This role involves building and managing a software-defined security operations architecture, focusing on detection engineering, threat response automation, and integrating AI/ML workloads.
Ansvarsområden
- Engineer Detection-as-Code using KQL, SPL, SQL, and Python, managed via version control and CI/CD pipelines.
- Create new monitoring use cases based on red team exercises, CTIC reports, and threat research.
- Automate threat response by building and integrating modular automation playbooks.
- Architect and scale enterprise deception capabilities (canaries, honeytokens).
- Configure and tune enterprise security controls (XDR, firewalls, cloud security, DLP).
- Partner with cross-functional teams to translate analytical needs into code and architecture.
- Integrate contextual data models, API gateways, and threat intelligence pipelines for AI/ML workloads.
- Develop detection and automation use cases across various data architectures (SIEM, data lakes, S3/Storage blobs, Federated Search).
- Mitigate security gaps through new detection rules, process improvements, and architectural designs.
- Build and maintain CI/CD pipelines with automated validation gates for secure content deployment.
- Utilize breach attack simulation and threat intelligence verification in validation workflows.
Krav
- Problem-solving mindset with the ability to bridge engineering and SOC operations.
- Strong background in SOC and/or SecOps engineering.
- Proficiency in Python or PowerShell.
- Understanding of software engineering best practices, APIs, and data structures (JSON/YAML).
- Deep proficiency in security query languages (Splunk SPL, KQL, SQL) and Python/TypeScript.
- Hands-on experience with Git and CI/CD platforms.
- Technical experience configuring and administering enterprise security controls (XDR/EDR/NDR, Firewalls, Cloud Security, DLP, Identity).
- Deep expertise in adversary tactics and techniques for deceptive asset placement.
Önskade kvalifikationer
- Familiarity with Graph Databases (Neo4j, Cosmos DB Gremlin) and entity relationship modeling.
- Experience integrating LLMs or building RAG pipelines.
- Experience with Docker, API Gateways, and Infrastructure-as-Code (Terraform/Bicep).
- Experience working with compiled languages (C# / .NET).
- Exposure to Operational Technology (OT) and manufacturing environments.
Förmåner
- Opportunity to shape sustainable transport and infrastructure solutions.
- Work with next-gen technologies and collaborative teams on a global scale.
- Occasional Travel
#Cyber Defense#Security Operations#Detection Engineering#Automation#Threat Research#AI/ML#Data Lakes#Cloud Security#DevOps#Infrastructure