4 дня назад
SOC Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Engineer (Cybersecurity): Monitoring, investigating, and responding to security threats across networks, endpoints, cloud platforms, and identity systems with an accent on SIEM/EDR operations, incident triage, and threat detection. Focus on analyzing complex logs, improving playbooks and alert quality, conducting threat hunting, and supporting containment and remediation during a 24/7 security operation.
Location: US Office; hybrid
Company
provides cybersecurity solutions that help managed service providers manage Microsoft Security policies across multiple tenants.
What you will do
- Monitor SIEM, EDR/XDR, and other security tools for real-time alerts and suspicious activity.
- Triage, investigate, document, and escalate security incidents using established playbooks.
- Analyze logs across networks, endpoints, cloud platforms, identity systems, servers, firewalls, and IDS/IPS.
- Support containment and remediation by isolating endpoints, collecting forensic artifacts, and validating indicators of compromise.
- Improve detection content by reducing false positives, closing detection gaps, and tuning alerts.
- Participate in threat hunting, proactive investigations, security-tool onboarding, and post-incident reporting.
Requirements
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, QRadar, or LogRhythm.
- Familiarity with EDR/XDR tools including CrowdStrike, Microsoft Defender, SentinelOne, or Cortex.
- Experience responding to security incidents in a SOC or cyber operations environment.
- Understanding of MITRE ATT&CK, threat actor behaviors, network security, TCP/IP, authentication flows, and identity logs.
- Strong analytical, written communication, collaboration, and decision-making skills in alert-driven environments.
- Ability to work in a hybrid setup from the US Office, including regular out-of-hours work for 24/7 operations.
Nice to have
- Exposure to Python or PowerShell scripting and automation.
- Security+, CySA+, GSEC, GCIA, GCIH, or CEH certification.
Culture & Benefits
- Flexible working hours with hybrid and remote working options.
- Out-of-hours work is compensated as overtime.
- Pension contribution scheme through Nest and competitive annual leave.
- Continuous learning, professional training, and career development opportunities.
- Inclusive workplace with regular team social events and employee recognition programs.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Cyber Threat Hunter
80 000 - 110 000$
10 дней назад
Sr. Detection Engineer
130 900 - 169 400$
7 дней назад
Security Operations Engineer (Cybersecurity)
91 200 - 118 600$
5 дней назад
Threat Detection Analyst III (Cybersecurity)
145 000 - 170 000$
6 дней назад
Senior OT Security Analyst
110 000$
11 дней назад
IT Security Operations Manager
90 000 - 100 000$