What You'll Do
SIEM Engineering
- Design, implement, and optimize SIEM solutions such as Splunk, Microsoft Sentinel, Google
SecOps, QRadar, and Elastic.
- Develop and enhance correlation rules, dashboards, alerts, and reports to improve threat visibility.
- Integrate security telemetry from cloud, endpoints, networks, and applications.
- Improve data ingestion, normalization, and parsing to increase detection accuracy and reduce
noise.
SOAR & Security Automation
- Build and maintain automated incident response playbooks using platforms such as Cortex XSOAR,
Splunk SOAR, or IBM Resilient.
- Automate alert triage, threat intelligence enrichment, and response actions.
- Partner with SOC analysts and threat hunters to streamline investigations and reduce response
times.
- Integrate SOAR platforms with ticketing systems, threat feeds, and security controls.
Security Operations Support
- Support incident response through actionable detections and automation-driven insights.
- Perform root cause analysis and develop engineering solutions to address recurring threats.
- Collaborate with compliance and audit teams to strengthen security controls.
- Create documentation and provide enablement sessions for SOC and IT teams.
Required Experience
What We're Looking For
- 3–8 years of cybersecurity experience, with strong hands-on experience in SIEM and/or SOAR
engineering.
- Experience working in a Security Operations Center (SOC) environment is highly preferred.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Technical Skills
- Hands-on experience with at least one SIEM platform:
- Splunk
- Microsoft Sentinel
- Google SecOps
- QRadar
- ArcSight
- Experience developing SOAR playbooks, workflows, and security automations.
- Scripting and automation skills using Python, PowerShell, or Bash.
- Knowledge of MITRE ATT&CK, NIST, CIS Controls, or similar cybersecurity frameworks.
- Familiarity with EDR/XDR, IDS/IPS, firewall technologies, and cloud security (AWS, Azure, or GCP).