Skip to content

Open nowPosted 4 days ago

Associate Security Content Engineer

Bitdefender54 open roles

Where
Bucharest, RO
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAssociate Security Content EngineerBitdefender · Bucharest, RO
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Bitdefender's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.4% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.5%1 day
  2. 3.5%3 days
  3. 7.4%7 days
  4. 13.1%14 days
  5. 34.4%30 days
This job: posted 4 days ago

The posting

Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry’s most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 180 of the world’s most recognized technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit https://www.bitdefender.com

Security Content Engineer – Managed Detection and Response

Our mission at Bitdefender is to reduce risk to our customers’ businesses so they can confidently pursue their goals. We are committed to delivering real, effective cybersecurity value—no fluff, no gimmicks. To support this mission, we are expanding our team with a Security Content Engineer role.

About Us

Bitdefender’s Managed Detection and Response (MDR) service is a rapidly growing division dedicated to protecting customers from real-world threats. Our team includes passionate cybersecurity professionals from around the globe, including seasoned defenders from military, intelligence, and leading cybersecurity organizations. We operate in a 24/7 environment, managing high-impact security incidents and continuously improving our defenses.

We believe in trust, accountability, and strong processes. Our team prioritizes collaboration and fosters a culture of ownership and problem-solving. If you are passionate about cybersecurity and want to work with others who take the mission seriously, this is the place for you.

About the Role

The Security Content Engineer plays a critical role in proactively identifying and mitigating threats across customer environments by developing and maintaining high-quality detection, investigation, and response content.

This role also supports the automation of SOC operations by designing and maintaining workflows and playbooks that improve triage, investigation, response, and overall analyst efficiency.

This is a full-time position aligned with a four-day, ten-hour schedule within Monday through Friday, with occasional on-call or weekend coverage depending on team needs.

You Will

  • Design and develop detection content that drives high-fidelity alerts and investigations.
  • Create and refine analytics rules to identify emerging threats and suspicious behavior.
  • Design, build, test, document, and maintain SOC automation and response playbooks using n8n.
  • Develop automated workflows supporting detection triage, enrichment, investigation, customer verification, response actions, and escalation.
  • Work with workflow management and orchestration platforms, such as Temporal and n8n, to support reliable and scalable security operations.
  • Integrate security platforms, data sources, APIs, and internal services into automated SOC workflows.
  • Maintain and tune customer environment baselines to reduce false positives and improve alert accuracy.
  • Conduct quality assessments on operational data to ensure reliability and relevance.
  • Develop threat-hunting queries and custom detection content based on threat intelligence.
  • Collaborate with MDR analysts to gather feedback and continuously improve detection content, automation, and playbooks.
  • Define and maintain data parsers to ensure consistent data normalization and availability.
  • Support investigations through ad hoc content development, workflow development, and detection tuning.
  • Review and respond to content-related tickets, automation requests, and feature requests.
  • Monitor automation performance, troubleshoot workflow failures, and improve playbook reliability.

About You

You are a hands-on engineer with a passion for security, detection engineering, threat hunting, and SOC automation. You enjoy solving difficult operational problems and turning analyst knowledge into repeatable, scalable workflows that improve customer security outcomes.

You Bring

  • Hands-on experience developing SOC automation workflows and security playbooks using n8n.
  • Experience working with workflow management or orchestration platforms, such as Temporal.
  • Experience creating automation for security triage, enrichment, investigation, and response processes.
  • Experience integrating security tools and data sources through APIs, webhooks, and other automated methods.
  • Experience working with detection and response platforms, such as SIEM, EDR, XDR, or SOAR technologies.
  • Strong understanding of threat-detection logic, signal-to-noise tuning, and false-positive reduction.
  • Familiarity with common attacker techniques, including the MITRE ATT&CK framework, and corresponding defensive countermeasures.
  • Knowledge of log formats and telemetry across multiple operating systems and security technologies.
  • Experience designing and implementing parsers for structured and unstructured data.
  • Scripting experience supporting security automation, detection engineering, and content development.
  • Ability to troubleshoot complex workflows and identify failures across interconnected systems.
  • Ability to collaborate across teams and communicate technical information effectively.

Bonus Qualifications

  • Experience with Bitdefender GravityZone, Graylog, N8N, or Swimlane.
  • Background in SOC operations or security content management within an MDR or MSSP environment.
  • Experience developing and refining detection and automation KPIs, such as baseline adherence, false-positive rates, playbook success rates, and analyst time savings.
  • Familiarity with software development practices, including version control, testing, peer review, and deployment pipelines.
  • Experience translating analyst investigation processes into documented and reusable automated playbooks.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Bitdefender's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Bitdefender's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Bitdefender's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.