Назад
Company hidden
8 дней назад

Security Operation Center L2 Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Cyprus
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operation Center L2 Engineer (Cybersecurity): Strengthening a Security Operations Center by onboarding and tuning log sources into SIEM, improving detection and response processes, and leading investigations of escalated security incidents with an accent on detection engineering, telemetry quality, and incident response. Focus on designing log pipelines and correlation logic, reducing false positives, reconstructing incident timelines, and coordinating containment, eradication, and recovery across technical teams.

Location: Limassol, Cyprus

Company

hirify.global is a technology company delivering high-performance solutions for partners in heavy-load industries.

What you will do

  • Onboard and maintain diverse log sources in SIEM, including parsing, field extraction, normalization, enrichment, and data mapping.
  • Design log pipelines, dashboards, alerts, detection rules, and correlation logic aligned with MITRE ATT&CK.
  • Assess telemetry coverage, troubleshoot ingestion issues, and optimize log volume, retention, quotas, and SIEM costs.
  • Design and improve SOC procedures, escalation matrices, playbooks, handover workflows, and L1 triage standards.
  • Lead investigation, containment, eradication, and recovery for escalated security incidents.
  • Coordinate with IT, DevOps, NOC, security, and business stakeholders; document incident reports, reviews, and remediation tracking.

Requirements

  • 3–5+ years of experience in SOC or security operations, with progression to L2 or equivalent.
  • Hands-on experience with SIEM platforms such as Splunk, Sentinel, QRadar, Elastic, or Datadog.
  • Experience onboarding firewalls, EDR, cloud platforms, identity providers, network devices, and applications into SIEM or observability platforms.
  • Practical incident response experience and knowledge of NIST 800-61, SANS IR, MITRE ATT&CK, attack techniques, and detection engineering.
  • Experience writing and tuning detection rules and correlation logic, reducing false positives, and using cloud-native logging in AWS, Azure, or GCP.
  • Query and scripting skills, such as DataPrime, Lucene query syntax, Python, or similar, plus strong documentation and communication skills.

Culture & Benefits

  • 24 working days of paid annual leave.
  • 6 days of paid sick leave.
  • Official employment and medical insurance.
  • Office coffee zone with fruit and snacks, plus a company-provided corporate lunch.
  • Gym and sports classes.
  • Greek and English language classes with partial company coverage.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →