2 месяца назад
Senior Cyber Operations Engineer (SIEM/SOAR & Security Platform Engineering)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Cyber Operations Engineer (SIEM/SOAR & Security Platform Engineering): Build, deploy, and support SIEM, Vulnerability, and AV/EDR services for Managed Hosting, Private Cloud, and Public Cloud solutions with an accent on SIEM infrastructure changes, detection engineering, and incident response operations. Focus on diagnosing and documenting customer implementations, improving service stability and resilience, and driving continuous improvements through new service standards and release approvals.
Company
delivers and manages mission-critical technology systems, including cybersecurity services.
What you will do
- Build, deploy, and support SIEM, Vulnerability, and AV/EDR services across managed hosting and cloud solutions.
- Develop and improve detection use cases, correlation rules, automated playbooks, and incident response capabilities.
- Administer and optimize security platforms such as Microsoft Sentinel, Splunk, QRadar, Cortex XSOAR, Chronicle, or Elastic Security.
- Diagnose and document customer implementations to enable timely resolution of service issues and SIEM alerts within SLAs.
- Drive continuous improvement by making fundamental SIEM infrastructure changes, defining standards, and contributing to service/product release reviews and approvals.
- Support escalations and mentor SOC team members during high-severity incident investigations, containment, and recovery.
Requirements
- 5+ years of hands-on cybersecurity engineering, SOC, or security operations experience in enterprise or managed services environments.
- Strong expertise in SIEM, SOAR, detection engineering, threat hunting, security automation, and cyber operations.
- Experience administering and optimizing security platforms including Microsoft Sentinel, Splunk, QRadar, Cortex XSOAR, Chronicle, or Elastic Security.
- Proven experience developing detection use cases, correlation rules, automated playbooks, and incident response capabilities.
- Strong knowledge of incident response, digital forensics, major incident management, threat intelligence (CTI), ASM, and active defense methodologies.
- Experience securing and monitoring cloud environments (AWS, Azure, GCP, or OCI), including Zero Trust, identity security, and cloud-native controls.
Culture & Benefits
- Hybrid-friendly work environment with a focus on well-being.
- Be Well programs supporting financial, mental, physical, and social health.
- Access to certification programs and learning opportunities (including Microsoft, Google, and Amazon), plus coaching and hands-on experiences.
- Continuous feedback and personalized development goals aligned with career ambitions.
- Culture emphasizing empathy, belonging, and shared success.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →