Apply now »

Senior Security Engineer, Cyber Defense

Bucharest, RO

BIC
Hybrid
Description: 

Join BIC World, a community of brands dedicated to creating ingeniously simple and joyful products that have been part of hearts and homes for over 75 years. We are committed to growing our iconic and innovative brands by reimagining everyday essentials in new, sustainable, and responsible ways.  

Our culture encourages a "roll up your sleeves and get the job done" mindset, ensuring self-starters, problem solvers, and innovative thinkers can truly thrive. At BIC World, you are empowered to take ownership of your career and use your unique perspective to make a meaningful, global impact on our mission. 

BIC Cybersecurity is seeking a highly skilled Senior Security Engineer to support global Cyber Defense operations and engineering initiatives focused on protecting the enterprise from evolving cyber threats. This role operates at the intersection of security engineering and SOC operations, requiring the ability to design, implement, and optimize security controls while actively responding to alerts, investigating incidents, and executing response playbooks.

The Senior Security Engineer will collaborate with a global, cross-functional team and third-party partners to enhance detection capabilities, automate response actions, and lead incident response efforts. This individual is expected to take decisive action during security events, continuously improve playbooks, and contribute to the overall maturity of Cyber Defense capabilities.

 

Key Responsibilities  

  • Design, implement, and maintain security controls across endpoint, network, and cloud platforms
  • Analyze, triage, and investigate alerts from SIEM, EDR, and other security tools; take appropriate containment, remediation, or escalation actions
  • Lead and actively participate in incident response activities, including coordinating efforts, driving investigations, and executing containment/eradication steps
  • Develop, maintain, and enhance incident response playbooks and standard operating procedures based on real-world incidents and threat intelligence
  • Engineer and optimize security tooling (e.g., SIEM, SOAR, EDR, NDR, etc.) to improve detection accuracy, reduce noise, and increase response efficiency
  • Automate alert triage, enrichment, and response actions using scripting or automated workflow capabilities available in multiple tools.
  • Perform root cause analysis, threat hunting, and deep-dive investigations across endpoints, network traffic, identity systems, and cloud environments
  • Integrate and onboard new log sources and security data into centralized monitoring platforms
  • Collaborate with infrastructure, cloud, and application teams to remediate vulnerabilities and improve overall security posture
  • Document incident findings, response actions, and lessons learned for reporting, metrics, and continuous improvement

Qualifications

Required

  • 5+ years of experience in Cybersecurity, Information Security, or related field
  • Strong hands-on experience with security engineering and SOC operations (incident response, alert triage, investigations) from working in a global SOC or Cyber Defense team environment
  • Ability to take ownership and execute rapid response actions during active security incidents with a sense of urgency under pressure
  • Proficiency in security tools and platforms such as SIEM (e.g., Google SecOps), EDR/XDR (e.g., CrowdStrike), MDR/SOAR collaboration/usage, firewall management (e.g., Cisco and Palo Alto), IDP/IDR, and log aggregation tools (e.g., Cribl)
  • Experience developing and executing incident response playbooks and procedures
  • Strong understanding of Windows and Linux operating systems, networking, Active Directory, and cloud platforms (Azure / Microsoft 365)
  • Experience analyzing logs and telemetry to detect threats and support investigations
  • Strong analytical, problem-solving, and decision-making skills in high-pressure situations
  • Strong communication skills with ability to take initiative to collaborate effectively with a globally diverse team and our business partners

 

Preferred

  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • Relevant certifications such as Security+ plus CISSP, CCSP, SSCP, GCIA, GCIH, GCED, EC CEH, or equivalent
  • Experience with automation (Python, PowerShell, or similar scripting) and/or use of ReliaQuest’s Greymatter platform
  • Experience with cloud security platforms and tooling, including CSPM and native controls within Azure as well as identity protection (Azure AD / Entra)
  • Experience with threat hunting and advanced detection engineering techniques
  • Familiarity with security frameworks such as NIST, CIS Controls, or MITRE ATT&CK, OWASP

Knowledge of DevSecOps practices and integrating security into CI/CD pipelines

 

BIC World is an Equal Opportunity Employer. We strongly commit to hiring people with different backgrounds and experiences to help us build better products, make better decisions, and better serve our customers. We do not discriminate based upon race, religion, color, national origin, gender, sexual orientation, veteran status, disability status, or similar characteristics. All employment is decided based on qualifications, merit, and business need.

BIC World is not seeking assistance or accepting unsolicited resumes from search firms for this employment opportunity. Regardless of past practice, all resumes submitted by search firms to any team member at BIC via email, or directly to a BIC team member in any form without a valid written search agreement in place for that position will be deemed the sole property of BIC, and no fee will be paid in the event the candidate is hired by BIC as a result of the referral or through other means.

Apply now »