Advanced Cyber Security Architect / Engineer (m/f/d)

Bucuresti, RomaniaFull-timePosted Jul 22, 2026

We have an opportunity for an Advanced Cybersecurity Architech / Engineer (m/f/d) to join us at Honeywell, in Bucharest, where you will participate in delivering and developing cyber security services for a wide range of industrial global customers. The position will have a direct reporting relationship to the Global Security Operation Center Manager and Incident Response Lead and work as part of a global managed services team. The position requires very good cyber security knowledge, excellent analytical skills and proficient handling of specific tools such as SIEMs and Security Orchestration, Automation and Response platforms. A successful candidate would be able to evaluate security incidents and determine true positives situations within an environment and provide context enrichment service before escalation to Level 3 Cyber Security Incident Response team as needed.

This is a hybrid role, 3 days at the office and 2 days work from home model.

Key responsibilities

  • Monitors SIEM, trouble tickets / email notifications and in-person escalations, logs from ICS infrastructure components (SCADA, HMI, PLC, RTU, Control Servers), applications or network devices such as switches, firewalls, IDS/IPS;
  • Design, implement, test Security Orchestration, Automation and Response processes and procedures;
  • SOAR playbook development and troubleshoot automation capabilities;
  • Examine the escalated tickets to determine if they are true positive or false positives.
  • Performs malware analysis, threat hunting and threat modeling activities; 
  • Assist forensic investigation by providing reports and other information;
  • Reviews and suggests improvements to control deployment process and installation procedures 
  • Develops and documents remediation recommendations for business owners to improve the control environment in which a security incident occurs. Recommendations must be easily understood by non-technical staff;
  • Provide recommendations and direction on the tuning of signatures, rules, alerts, parsers, and custom scripts within the monitoring solutions;
  • Participates in root cause analysis and helps with the orchestration of remediation;
  • Understand defense in depth strategies and apply those to Client’s environment;
  • Creates and disseminates security related notifications for internal staff (for example: trends, developments, changes in capabilities);
  • Acts as L2 Escalation layer in the SOC.
  • Mentors Level 1 SOC Analysts;
  • Creates manuals, guides and knowledge base entries;
  • Keep abreast of latest security and privacy legislation, emerging threats, regulations, advisories, alerts, and vulnerabilities pertaining to HCE OT IR SOC and its customers;
  • Remains knowledgeable of our current solution portfolio and the technical specificities of our offerings. 

 

 

 

Key skills and qualifications

  • Bachelor’s degree in a computer related field such as Computer Science, Computer information systems or electronics;
  • Minimum of 3 years’ experience in cyber security SOC  industry;
  • Minimum of 5 years’ experience in Information Technology;
  • Strong diagnostic and analytical skills including problem solving, trouble shooting, management of priorities and self-direction to resolve complex issues;
  • Effective written and verbal skill to enable strong communication capabilities;
  • Information Technology certifications: ITIL Foundations;
  • Security Certifications: CCNA, CompTIA Security+, GCIH, or other similar certifications;
  • Experience to automate tasks and integrate systems with Python;
  • Experience with SPLUNK or CHRONICLE SIEM platforms and logging solutions.

 

We Value:

  • GCFA or CEH or other similar certifications;
  • Understand Advanced SOAR methodology;
  • Understand ICS communication protocols such as Modbus, Profibus, DNP3, S7comm and others.
  • Ability to write documentation and summaries;
  • Experience working in a client facing Cyber SOC environment;
  • Experience securing industrial or corporate networks and assets against cyber threats;
  • Knowledge of ICS environments;
  • Knowledge of cybersecurity frameworks such as MITRE ATT&CK, MITRE for ICS and NIST. 

 

Our offer

  • 3 days from office, 2 days from home hybrid work arrangement to support your work-life balance
  • Competitive Salary regularly increased based on your performance
  • Enjoy 25 vacation days per year, plus extra days off for life's special events
  • We provide meal vouchers
  • Flexible benefits basket with monthly budget allocated (top up medical insurance, life insurance, pension, vacation/ cultural/ fuel vouchers)
  • Medical Insurance Plan paid by the company
  • Christmas and Easter bonuses
  • Recognition & referral bonus programs
  • Comprehensive induction, ongoing training and development to set you up for success
  • In-house and external learning platforms (Udemy) to continue to expand your skills
  • Work experience opportunities to help you grow your career with us
  • Global employee networks to help you connect and grow
  • Employee Assistance Program - Free and confidential service to help with any difficulties regarding work, life and personal or family matters
  • In case of unfortunate events, we support you by offering you free days and financial support (handled on a case by case basis) or Family financial aids
  • Access Integrity line - Any workplace issues or violations that need to be raised in good faith, can be communicated in a safe, private and confidential environment
  • Your family is growing while working at Honeywell? We congratulate you by offering special bonuses
  • Frequent Employee Engagement activities fostering an inclusive and diverse work environment
  • Fresh fruit days in the office

 

 

 

Join us now and be part of a global team of thinkers, innovators, dreamers, and doers who make the things that make the future!

#TheFutureIsWhatWeMakeIt

#LiHybrid

 

 

We are an equal opportunity employer and value diversity at our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform crucial job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free