About UBQ.io UBQ.io is a global technology service provider dedicated to building a more sustainable, independent, and equitable future. We partner with global companies across industries, including AI, blockchain, software, biotech, and education, to transform bold ideas into real, meaningful solutions.
Our expertise spans technology consulting, AI and Machine Learning development, Blockchain integration, and global team collaboration. With a worldwide network of specialists, we help organizations stay ahead in a rapidly evolving digital landscape.
At UBQ.io, we don’t just advise, we collaborate. Our commitment to innovation, sustainability, and social responsibility guides everything we do as we help clients build technologies that empower people, communities, and industries to thrive.
About The Role The Cybersecurity Operations Engineer is responsible for the hands-on implementation, configuration, and optimization of the organization's core security technologies, as well as for writing detections, investigating incidents, and proactively hunting for threats.
This role goes beyond monitoring and alerting: the focus is on deploying and tuning the platforms that protect endpoints, network access, web applications, and log data, and on using them to find, understand, and respond to real threats. The ideal candidate has strong technical depth, has personally implemented security tooling in production environments, and thrives in a fast-paced setting where accuracy, engineering discipline, and security are essential.
Key Responsibilities
- Implement, configure, and maintain Endpoint Detection and Response (EDR) platforms, including policy tuning, detection rule management, and response actions.
- Deploy and manage Security Service Edge (SSE) solutions,
including Secure Web Gateway (SWG) and Zero Trust Network Access (ZTNA) components.
- Administer and fine-tune the Security Information and Event Management (SIEM) platform, including log source onboarding, correlation rule development, dashboards, and alert optimization.
- Lead the evaluation, rollout, and integration of new security tooling, ensuring proper documentation and alignment with the broader security architecture.
- Write, test, and tune detection content across the security stack, including SIEM correlation rules, EDR custom detections, and WAF rules, mapping coverage to frameworks such as MITRE ATT&CK.;
- Investigate security incidents end to end, from initial triage through analysis, containment, eradication, and post-incident documentation, coordinating with relevant teams throughout.
- Proactively threat hunt across endpoint, network, and log data to uncover suspicious activity that existing detections may have missed, and turn findings into new detections.
- Develop and maintain technical documentation, standard operating procedures, and incident response and detection playbooks.
- Collaborate with IT, infrastructure, and application teams to embed security controls and support day-to-day operations.
- Support vulnerability management and drive continuous improvement of the organization's overall security posture.
Requirements
- Bachelor's degree in Information Technology,
Cybersecurity, Computer Science, or a related field (or equivalent practical experience).
- At least 3 years of hands-on experience implementing and managing core security technologies such as EDR, SSE, SIEM, and WAF.
- Demonstrated experience deploying, configuring, and tuning these platforms in production, not only reviewing the alerts they generate.
- Experience gained in a Security Operations Center (SOC) is a plus, provided it includes hands-on implementation and engineering work rather than monitoring alone.
- Hands-on experience writing and tuning detections, investigating incidents, and conducting threat hunts, ideally with familiarity with the MITRE ATT&CK; framework.
- Excellent understanding of network security, endpoint security, cloud security, and Zero Trust principles.
- Relevant certifications such as Security+, GCIA, GCIH, OSCP or vendor-specific credentials are a plus.
- Strong troubleshooting and problem-solving skills with a high attention to detail.
- Ability to handle sensitive information responsibly and securely.
- Good communication skills and the ability to work effectively across technical and non-technical teams.
About You You are a hands-on security practitioner who enjoys building and strengthening defenses rather than only watching dashboards. You have personally stood up and tuned the tools that keep an organization safe, you write your own detections, and you would rather go hunting for a threat than wait for an alert to tell you it is there. You are structured, reliable, and curious about new technologies, and you enjoy working closely with both technical teams and end users to raise the security bar across the environment.
📌 Cybersecurity Operations Engineer (Europe 100% remote) (Italia)
🏢 UBQ.io
📍 Italia