Operations Advisor (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Operations Advisor (Cybersecurity): Leading detection engineering and technical account management for managed security clients with an accent on SIEM optimization, threat detection strategy, and risk-based advisory. Focus on identifying coverage gaps, tuning detection rules, and partnering with SOC/DFIR teams to deliver measurable security outcomes.
Location: Hybrid (United Kingdom), 2–3 days in office required.
Company
is a global cybersecurity firm providing managed detection and response, identity management, and risk programs powered by their proprietary entity fabric, Meridian.
What you will do
- Own and maintain detection coverage aligned to the Rule Set.
- Lead tuning and optimization of detection rules across enterprise SIEM platforms.
- Identify, prioritize, and remediate detection gaps to improve client security maturity.
- Oversee the technical account relationship and lead cadence calls regarding detection performance.
- Translate technical findings into business-relevant risk insights for clients.
- Partner with SOC and DFIR teams during incident escalations.
Requirements
- 3–5 years of experience in detection engineering or security operations.
- Hands-on proficiency with enterprise SIEM platforms like Splunk, Microsoft Sentinel, or Chronicle.
- Demonstrated experience writing and tuning detection rules in production environments.
- Experience working in an MSSP environment serving multiple clients.
- Proficiency in SIEM query languages such as SPL, KQL, or YARA-L.
- Relevant certifications such as GCIA, GCIH, GCDA, or vendor-specific SIEM credentials.
Nice to have
- Familiarity with SOAR platforms and automation-assisted workflows.
- Experience with threat hunting methodologies and retrohunt program execution.
Culture & Benefits
- Hybrid work model with 2–3 days in office.
- Comprehensive medical and life insurance coverage.
- Retirement match program.
- Professional development reimbursement and access to LinkedIn Learning.
- Paid time off including sick, casual, and volunteer leave.
- Mobile phone reimbursement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →