L3 SOC Internal Analyst

zeissgroup· Carl Zeiss Digital Innovation Hungary Kft.
Apply Now ↗
📍 Budapest - ZDI📍 MiskolcFull time

About this role

ZEISS is technology and innovation. Founded in Germany, in 1846, ZEISS is an internationally leading technology enterprise operating in the optics and optoelectronics industries across 50 countries.  

As a company wholly owned by a foundation, ZEISS is committed to responsibility in all its activities. As a pioneer in scientific optics, it's employees across the globe continue to push the boundaries of what is possible. With a strong focus on quality and innovation, ZEISS creates value for its customers and helps shape new ways of seeing the world.  

We’re looking for a L3 SOC Internal Analystto join us Budapest, Hungary.

Your Role 

As L3 SOC Internal Analyst, you lead the day‑to‑day operations of our Cyber Defense Center (CDC) and set the direction for effective monitoring, investigation, and incident response across all SOC tiers. You act as the primary interface to our Managed Security Service Provider (MSSP) and as the senior escalation point for our most complex and high‑impact investigations. Beyond the operational lead role, you shape and steer our threat hunting activities, ensuring they are risk‑driven, measurable, and firmly anchored in CDC governance. In close collaboration with engineering, CIRT, threat intelligence, and other capability functions, you drive the continuous evolution of our detection and response capabilities and help strengthen the organization's overall security posture. 

  

The role of L3 SOC Internal Analyst will involve: 

  • Act as the single point of contact for the MSSP conducting SOC 24/7 monitoring and manage vendor performance, outputs, and service assurance. 
  • Serve as the L3 escalation point for complex alerts, incidents, and investigations, providing senior technical expertise and decision‑making. 
  • Coordinate and lead response to incidents across SOC tiers and ensure effective handover to the CIRT for high and critical cases. 
  • Own the SIEM/SOAR detection lifecycle, including log source onboarding, continuous fine‑tuning of detection rules, and review/validation of use cases. 
  • Define threat hunting objectives, aligning them with the CDC’s strategic goals and coordinate MSSP-led threat hunting activities. 
  • Develop and produce monthly KPI dashboards and reporting to demonstrate SOC performance and drive improvements. 
  • Work with the engineering team to increase log coverage, telemetry quality, and overall visibility across the monitored environment. 
  • Serve as Duty Operational Manager on a rotational on‑call basis (24/7/365), providing senior operational oversight and incident support out of hours. 

Your Experience 

  • Degree in Computer Science, IT Security, or a related field, or equivalent work experience. 
  • Several years of experience in a Security Operations Center, incident response, or threat detection role, including senior/L3 responsibilities and team or vendor coordination. 
  • Excellent communication and stakeholder management skills, with the ability to translate technical findings for both technical and executive audiences. 
  • Experience in incident response, threat detection, or security monitoring, with expertise in detection and response workflows. 
  • Strong ability to work under pressure, prioritize critical incidents, make rapid decisions, and support on‑call escalation. 
  • Hands‑on experience with SIEM, SOAR, and EDR technologies, as well as a solid understanding of detection technologies such as IDS/IPS, DLP, and WAF. 
  • Understanding of security threats and attack frameworks such as MITRE ATT&CK and the Cyber Kill Chain. 
  • Ability and drive to review, manage and continously improve vendor performance, contracting and metrics with clear accountability and follow‑through. 
  • Experience leading threat hunting activities, including defining hypotheses, objectives, and measurable outcomes. 
  • Fluency in English.

It would be desirable if you had:  

  • German is a plus.
  • Familiarity with EU cybersecurity regulations relevant to SOC operations (e.g., NIS2 Directive) is a plus. 
  • Professional certifications such as CISM, GCIA, GCIH, or CISSP are a plus. 

Your Benefits 

If you join ZEISS, you will have access to a range of benefits, including: 

  • Technology stack: Modern and cutting-edge technology stack with opportunities to experiment and innovate within a high-tech group 
  • Flexible work options: 40-60% hybrid work option to provide flexibility and work-life balance 
  • Additional benefits: Annual flexible benefits that include cafeteria options, private health plans, and annual reward 
  • Extra option: Company parking space in the underground garage of the office building can be reserved 
  • Contribution: Opportunity to directly contribute to the development of innovative products through software delivery 
  • Supportive work environment: working in a team composed of excellent teammates and a supportive lead who collaborate to guide and support professional development from day one 
     

At ZEISS we encourage creative thinking and innovation. We work in dynamic and interdisciplinary teams and offer individual development perspectives and flexibility in organizing your work. We care about our employees and take responsibility for improving society and preserving our environment. These core values have shaped our corporate culture at ZEISS for over 175 years. 

Join our inclusive and diverse #teamZEISS and enable the digital future for ZEISS and our synergy clients. 
 

Apply now to take the next step in joining ZEISS, where you can push technological boundaries, shape markets and contribute to the advancement of society.  

Your ZEISS Recruiting Team:

Bartha Györgyi, Fedor Fanni, Sturcz Noémi, Wenner Lili

Frequently Asked Questions

Is the salary disclosed for the L3 SOC Internal Analyst position at zeissgroup?
The salary for this L3 SOC Internal Analyst role at zeissgroup is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the L3 SOC Internal Analyst position at zeissgroup located?
This L3 SOC Internal Analyst role at zeissgroup is based in Budapest - ZDI, Miskolc. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the L3 SOC Internal Analyst role at zeissgroup full-time or part-time?
This is listed as a Full time position. It is posted as a L3 SOC Internal Analyst role in the Carl Zeiss Digital Innovation Hungary Kft. department at zeissgroup.
Which team or department does the L3 SOC Internal Analyst at zeissgroup belong to?
This L3 SOC Internal Analyst position is part of the Carl Zeiss Digital Innovation Hungary Kft. department at zeissgroup. See the full job description for more information about the team structure and responsibilities.
How do I apply for the L3 SOC Internal Analyst position at zeissgroup?
Click the "Apply Now" button on this page. You will be redirected to zeissgroup's official application portal hosted on workday where you can submit your application directly.
When was the L3 SOC Internal Analyst job at zeissgroup posted?
This L3 SOC Internal Analyst position at zeissgroup was posted on Jul 17, 2026. Apply as soon as possible — early applications are often reviewed first.
L3 SOC Internal Analyst
zeissgroup
Apply for this role ↗

You'll be redirected to zeissgroup's official application page on Workday.