Senior SOC Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior SOC Engineer (Cybersecurity): Monitoring and responding to security incidents across infrastructure with an accent on SIEM management, threat detection logic, and incident investigation. Focus on designing detection as code, conducting hypothesis-based threat hunting, and enhancing security telemetry across Linux, cloud, and Kubernetes environments.
Location: Must be based in or able to relocate to Almaty, Kazakhstan. Work format: Hybrid.
Company
A global ride-hailing and multi-service tech company focused on fair pricing and social impact across 48 countries.
What you will do
- Act as the L3 escalation point for complex security incidents and lead advanced investigations.
- Design, implement, and improve SIEM detection rules and response playbooks using a Detection as Code approach.
- Translate MITRE ATT&CK tactics into practical detection logic for Linux, cloud, and microservices.
- Drive hypothesis-based threat hunting to identify sophisticated attacker behavior.
- Design and mature SOC processes, operational metrics, and detection strategy.
- Collaborate with cross-functional teams to streamline workflows and improve security visibility.
Requirements
- 5–7+ years of experience in SOC environments, with strong hands-on L3-level expertise.
- Expert knowledge of SIEM platforms (Splunk, Elastic, etc.) including correlation queries and parsing.
- Deep knowledge of Linux, container runtimes, and Kubernetes security telemetry.
- Practical experience with Detection as Code methodologies and Git.
- Strong understanding of attacker TTPs (MITRE ATT&CK) and incident response lifecycles.
- Experience with cloud security monitoring in AWS or GCP.
Nice to have
- Experience with CI/CD pipelines (GitHub Actions) for security content deployment.
- Building or maturing Threat Intelligence and Threat Hunting processes.
- Relevant security certifications such as SANS or Offensive Security.
Culture & Benefits
- Official employment with a stable salary and health insurance.
- Hybrid work mode with flexible scheduling.
- Relocation package provided for candidates from other regions.
- Access to professional counseling including psychological, financial, and legal support.
- Training programs and support for additional professional certifications.
- All necessary work equipment provided.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →