Job Description
JOB Summary:
The SIEM & SOC Senior Specialist will be responsible for leading the migration of the SIEM platform from the existing
environment to a new solution. This role involves designing and developing new detection use cases, optimizing and
refining them prior to deployment, and ensuring seamless onboarding into the new platform. The specialist will also
establish new operational processes, enhance and modify existing procedures as required, and drive adherence to
security and compliance standards, ensuring achievement of a 100% compliance score.
Mandatory Skills:
SOC Operation Leadership
- Own daily SOC operations, ensuring continuous monitoring, triage, investigation, and response across all
environments.
- Define and enforce SOC operating model (tiers, shift model, handovers, runbooks, playbooks, escalation matrix).
- Establish and track KPIs/SLAs (MTTD, MTTR, false positive rate, detection coverage, case backlog, usecase health).
- Drive operational excellence: backlog management, case quality reviews, postincident reviews, and continuousimprovement.
- Able to plan, build and run the SOC tool from scratch, requires having hands-on SIEM tool migration experience.
- Prior working experience to handle different types of Audits such ISO 27001 and able to create roadmap for Audit gaps
closure on timebound manner.
SIEM & Detection Engineering
- Administer and maintain SIEM platform health (parsers, ingestion pipelines, data models, indexing, retention,
performance).
- Onboard and normalize log sources (network, endpoint, identity, cloud, application) to meet coverage targets.
- Design, tune, and maintain detections (rules, correlations, ML/UEBA) aligned to MITRE ATT&CK and threat scenarios.
- Develop and maintain dashboards, metrics, usecase catalogs, and detection lifecycle management processes.
Incident Handling & Response
- Lead incident response from validation through containment, eradication, recovery, and lessons learned.
- Coordinate crossfunctional responders (IT ops, network, application, legal/IR) and manage stakeholder
communications.
- Prepare and maintain IR plans, playbooks, communications templates, and evidence handling procedures.
- Conduct rootcause analysis and drive corrective actions to prevent recurrence.
Threat Hunting & Intelligence
- Run proactive hunts across SIEM/EDR/identity telemetry based on TTPs, IOCs, and hypothesisdriven scenarios.
- Operationalize internal/external threat intelligence and OSINT to improve detections and coverage.
1.1.1 Stakeholder Communication
- Provide timely, clear communication during incidents; prepare executive summaries and afteraction reports.
- Partner with IT Ops, Network, Application, and Business stakeholders to balance risk, speed, and user impact.
Qualifications & Experience:
- Bachelors degree in Computer Science, Information Security, Engineering, or equivalent experience.
- 12-15 years in Security Operations with 5+ years leading SOC teams or major incident response programs.
- Expertlevel handson experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, LogRhythm, QRadar) including
admin and detection engineering.
- Strong incident handling expertise across containment, eradication, recovery, and lessons learned.
- Demonstrated experience with EDR/XDR, SOAR automation/orchestration, and case management tools.
- Handson network security knowledge (firewalls, IDS/IPS, WAF, VPN, proxies, NAC) and packet/log analysis.
- Vulnerability management lifecycle experience using enterprise scanners and remediation governance.
- Experience integrating cloud and identity telemetry; familiarity with Azure/M365 security preferred.
- Knowledge of frameworks and models: MITRE ATT&CK, NIST 80061 IR, NIST CSF, ISO 27001.
- Excellent communication, stakeholder management, and executive reporting skills.
- Audit participation experience is must
Preferred Certifications:
- Security+: CompTIA Security+
- SIEM/EDR vendor certifications (e.g., Splunk, Microsoft, CrowdStrike).
- Incident response/forensics (e.g., GCFA, GNFA, GCIH).
- Cloud security (e.g., AZ500, SC200, CCSP).
- Network security (e.g., NSE, PCNSA/PCNSE, CCNP Security).
Tools & Platforms (indicative):
- SIEM: Splunk, Microsoft Sentinel, LogRhythm, QRadar
- EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike, SentinelOne
- SOAR: Splunk SOAR, Cortex XSOAR, Sentinel playbooks/Logic Apps
- Vulnerability: Qualys, Tenable, Rapid7
- Network: Palo Alto, Fortinet, Cisco, F5/WAF, Zscaler/Proxies
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
