15 дней назад
SIEM Content Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SIEM Content Engineer (Cybersecurity): Developing and configuring XDR, SIEM, and SOAR content, detection rules, dashboards, pipelines, and incident response playbooks across on-premises and cloud environments with an accent on threat detection, data normalization, and security content performance. Focus on integrating security platforms, analyzing complex attack scenarios, and continuously improving defenses against evolving cyber threats.
Location: Budapest, Hungary
Company
operates and modernizes mission-critical technology systems and provides cybersecurity and security resiliency services for enterprise customers.
What you will do
- Develop SIEM, SOAR, and XDR use cases, building blocks, detection rules, dashboards, workbooks, and notebooks.
- Design, configure, deploy, and support IBM, Microsoft, and Palo Alto security solutions across on-premises and cloud environments.
- Develop and fine-tune incident management use cases, playbooks, runbooks, event pipelines, and flow pipelines.
- Perform data classification and normalization and integrate security content with multiple platforms.
- Monitor content performance, troubleshoot issues, document findings, and drive continuous improvement.
- Collaborate with SOC analysts, cyber threat intelligence, threat hunting, and SOC management teams while tracking emerging attack techniques.
Requirements
- Programming experience with Python, PHP, Bash, or PowerShell.
- Proficiency with blue-team tools and methodologies, including SIEM, SOAR, EDR/XDR, MITRE ATT&CK, and log analysis.
- Understanding of networking, computing, operating systems, and their application to security practices.
- Ability to research emerging threats and technologies and translate findings into training content.
- Strong written and verbal English communication skills are required.
Nice to have
- CISSP, CISM, GIAC, or similar certification, or equivalent experience.
- Experience with project management.
- Experience with KQL, AQL, or XQL query languages.
- Understanding of threat actor tactics, techniques, and procedures and defensive methods.
Culture & Benefits
- Hybrid-friendly culture focused on employee well-being and belonging.
- Financial, mental, physical, and social well-being programs.
- Access to certifications, coaching, hands-on learning, and development opportunities.
- Career planning, personalized development goals, and continuous feedback.
- Opportunities to grow into technical leadership, consulting, or go-to-market roles.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →