Job Description
What would you do?
• Design, develop, and optimize high-fidelity detection rules across SIEM, EDR/XDR, cloud, identity, email, and network security platforms. • Assess telemetry coverage across endpoint, network, identity, cloud, and SaaS environments, identifying visibility gaps and recommending improvements. • Translate threat intelligence, threat hunting findings, and incident learnings into actionable detections and use cases. • Continuously improve detection fidelity by reducing false positives, eliminating duplicate alerts, and expanding detection coverage. • Lead technical investigations for complex and high-severity security incidents, providing guidance on containment, eradication, and recovery. • Develop and maintain automation and orchestration workflows using SOAR platforms to improve SOC efficiency. • Support cloud security monitoring across AWS, Azure, and GCP environments. • Evaluate and improve security visibility for containers, Kubernetes, and modern application environments. • Create and maintain technical documentation, detection logic, runbooks, and operational procedures. • Stay current with emerging cyber threats, attack techniques, and advancements in security technologies. AI Enabled Qualifications: • Demonstrated ability to leverage AI-powered tools for IT operations, incident analysis, workflow automation, and operational reporting. • Proactive in adopting emerging AI technologies to enhance system reliability, team productivity, and data-driven decision-making. Qualifications & Requirements • 5+ years of experience in Security Operations, SOC Engineering, Detection Engineering, or Incident Response. • Hands-on experience administering enterprise SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, Elastic, IBM QRadar. • Strong understanding of SIEM architecture, log management, parsing, normalization, correlation rules, data models, and performance optimization. • Strong knowledge of MITRE ATT&CK, cyber kill chain, threat detection methodologies, and attacker tactics and techniques. • Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike Falcon, SentinelOne, or Cortex XDR. • Working knowledge of cloud security services across AWS, Azure, or Google Cloud Platform. Strong understanding of Windows, Linux, Active Directory, Entra ID, networking protocols, and authentication technologies. • Experience with scripting or automation using Python, PowerShell, or Bash. • Experience working with SOAR platforms and security automation. • Strong analytical, troubleshooting, and problem-solving skills. • Excellent communication skills with the ability to collaborate across technical and business teams.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
