обновлено 6 дней назад
Operations Advisor, Cyber Defense Operations
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Operations Advisor, Cyber Defense Operations (SIEM/Detection Engineering): Improving detection coverage and security maturity for assigned clients with an accent on detection rule tuning, gap remediation, and risk-based advisory. Focus on leading production detection engineering across enterprise SIEM platforms, collaborating with SOC and DFIR teams, and translating technical findings into measurable client outcomes.
Location: United Kingdom; hybrid work with 2–3 days in the office
Company
provides identity and access management, exposure management, risk programs, and managed detection and response services supported by its Meridian entity fabric and AI-augmented security operations.
What you will do
- Own and maintain client detection coverage aligned with the Rule Set.
- Lead tuning and optimization of detection rules across enterprise SIEM platforms.
- Identify, prioritize, and remediate detection gaps using incident insights.
- Serve as the technical owner and trusted advisor for assigned client accounts.
- Lead technical cadence calls focused on detection performance, gaps, and outcomes.
- Partner with SOC and DFIR teams during escalations and translate findings into business-relevant risk insights.
Requirements
- 3–5 years of experience in detection engineering, security operations, or a related discipline.
- Hands-on experience with one or more enterprise SIEM platforms, such as Splunk, Microsoft Sentinel, or Chronicle.
- Experience writing and tuning production detection rules and using multiple query languages, including SPL, KQL, or YARA-L.
- Experience in a managed security services or MSSP environment serving multiple clients.
- Familiarity with SOAR platforms, automation-assisted detection workflows, threat hunting, and retrohunt programs.
- Relevant certifications such as GCIA, GCIH, GCDA, or SIEM vendor certifications.
Culture & Benefits
- Hybrid work model with 2–3 days in the office.
- Employee-covered medical insurance and life insurance.
- Retirement match program, paid time off, sick and casual leave.
- Maternity, paternity, bereavement, and volunteer leave.
- Professional development reimbursement and access to LinkedIn Learning courses.
- Mobile phone reimbursement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →