SOC Engineer
Professional Requirements
Log Source Mapping: Identify and map organizational log sources intended for ingestion into the SIEM platform. Understand which security-relevant logs are available, assess their value, and ensure they are properly collected and ingested.
SIEM Integrations: Design and implement end-to-end integrations between organizational systems and the enterprise SIEM platform, including planning, onboarding, validation, and troubleshooting.
SIEM Rule Development: Develop and maintain SIEM detection rules end-to-end, including rule name, description, severity, MITRE ATT&CK mapping, drill-down queries, investigation guidance, response recommendations, and continuous tuning to improve detection quality.
SOAR Experience: Hands-on experience with SOAR platforms, including building and maintaining automation playbooks to improve incident response efficiency and reduce manual effort.
AI Adoption: Proven experience using AI tools to improve productivity, accelerate technical work, and enhance the quality of daily operations. Candidates who have already integrated AI into their day-to-day workflow will have a significant advantage.
Personal Attributes
Proactive and Solution-Oriented: Able to identify issues independently while proposing practical solutions, rather than only escalating problems.
Strong Communication Skills: Maintain ongoing communication and provide regular status updates to the SOC Manager as responsibilities evolve.
Strong Technical Skills: The most critical requirement for this role. The ideal candidate is highly technical, possesses strong analytical abilities, and can independently solve complex technical challenges.
Critical Thinking and Attention to Detail: Ability to analyze situations thoroughly, challenge assumptions, and focus on details to deliver high-quality outcomes.
On-Call Rotation
- Participation in the team's on-call is required as part of this role, including availability to respond to security incidents outside of regular business hours when needed.