Назад
1 день назад

SOC Specialist (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Malta
vacancy_detail.hirify_telegram_tooltipВакансия из Telegram канала -

Мэтч & Сопровод

Покажет вашу совместимость и напишет письмо

Описание вакансии

TL;DR
SOC Specialist (Cybersecurity): Building and maturing security detection and incident-response capabilities with an accent on Microsoft Sentinel, Defender XDR, KQL detections, and log-source integration. Focus on leading incident investigations, conducting threat hunting, automating SOC workflows, and mapping adversary behavior to MITRE ATT&CK.

SOC Specialist

Company

SCRYPT

Conditions

6 days ago

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will build and mature security detection and response capabilities. You will investigate security events, lead incident response, develop KQL detections, integrate log sources, conduct threat hunting, automate SOC workflows, and communicate findings clearly to technical and non-technical stakeholders.

Requirements

  • At least 3 years of hands-on SOC experience
  • Deep expertise with Microsoft Sentinel
  • Proficiency with Microsoft Defender XDR
  • Advanced KQL skills
  • Experience integrating and managing log sources
  • Ability to lead or independently execute incident response investigations
  • Understanding of MITRE ATT&CK and adversary techniques
  • Experience managing alert escalations
  • Knowledge of ISO 27001 or NIST frameworks
  • Fluent English

Responsibilities

  • Monitor, analyze, and investigate security events in Microsoft Sentinel and Defender XDR
  • Lead incident response from triage through post-incident review
  • Write, tune, and optimize KQL detection rules
  • Onboard and maintain log sources across endpoint, identity, cloud, and network layers
  • Manage alert escalation workflows
  • Map attacker behavior to MITRE ATT&CK
  • Conduct proactive threat hunting
  • Build SOC automation workflows
  • Develop SOC playbooks, runbooks, and escalation procedures
  • Communicate technical findings to executive and non-technical audiences
  • Collaborate with IT, DevOps, and engineering to strengthen security

Benefits

  • Hybrid role based in Malta with flexibility within European hours

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник -