Job Overview
We are seeking an experienced Cyber Security Engineer with expertise in Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. This role is responsible for designing, implementing, and maintaining enterprise security monitoring and automated incident response solutions to strengthen an organization's cybersecurity posture.
You will work closely with security operations, threat analysts, and IT teams to improve threat detection, automate response workflows, and enhance overall security operations.
Key Responsibilities
SIEM Administration & Engineering
- Design, implement, configure, and optimize SIEM platforms.
- Develop and maintain correlation rules, dashboards, alerts, and reports for security monitoring.
- Integrate logs and telemetry from networks, endpoints, cloud platforms, and applications.
- Optimize data ingestion, parsing, and normalization to improve detection accuracy and platform performance.
- Monitor and continuously enhance SIEM effectiveness through tuning and rule optimization.
SOAR Development & Automation
- Implement and administer SOAR solutions.
- Design and develop automated incident response playbooks.
- Automate alert triage, threat intelligence enrichment, and security workflows.
- Integrate SOAR with ticketing systems, security tools, and threat intelligence platforms.
- Partner with security operations teams to reduce manual effort and improve response times.
Security Engineering
- Support incident response activities by developing actionable detections and automation.
- Perform root cause analysis on recurring security incidents and implement preventive improvements.
- Assist with maintaining security controls that align with compliance and regulatory requirements.
- Create technical documentation and provide knowledge sharing to security and IT teams.
- Participate in continuous improvement initiatives for security monitoring and response capabilities.
Qualifications
Education & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field.
- At least 5 years of experience in SIEM and/or SOAR administration, engineering, or security operations.
- Experience working in a Security Operations Center (SOC) environment is an advantage.
Technical Skills
- Hands-on experience with one or more enterprise SIEM platforms.
- Experience implementing and managing SOAR solutions, including automation playbook development.
- Proficiency in scripting or automation using Python, PowerShell, Bash, or similar languages.
- Strong understanding of cybersecurity frameworks such as MITRE ATT&CK, NIST, and CIS Controls.
- Experience with endpoint security, network security technologies, threat intelligence platforms, and cloud security environments.
- Familiarity with AWS, Microsoft Azure, or Google Cloud security services is an advantage.
Soft Skills
- Strong analytical and problem-solving abilities.
- Excellent written and verbal communication skills.
- Ability to work independently while collaborating effectively with cross-functional teams.
- Strong documentation and process improvement skills.