Skip to content

SOC Engineer

Citadel Cyber SecurityTel Aviv, IsraelJuly 31, 2026
On-site
Full-time
SOC

Professional Requirements

  • Log Source Mapping: Identify and map organizational log sources intended for ingestion into the SIEM platform. Understand which security-relevant logs are available, assess their value, and ensure they are properly collected and ingested.

  • SIEM Integrations: Design and implement end-to-end integrations between organizational systems and the enterprise SIEM platform, including planning, onboarding, validation, and troubleshooting.

  • SIEM Rule Development: Develop and maintain SIEM detection rules end-to-end, including rule name, description, severity, MITRE ATT&CK mapping, drill-down queries, investigation guidance, response recommendations, and continuous tuning to improve detection quality.

  • SOAR Experience: Hands-on experience with SOAR platforms, including building and maintaining automation playbooks to improve incident response efficiency and reduce manual effort.

  • AI Adoption: Proven experience using AI tools to improve productivity, accelerate technical work, and enhance the quality of daily operations. Candidates who have already integrated AI into their day-to-day workflow will have a significant advantage.

Personal Attributes

  • Proactive and Solution-Oriented: Able to identify issues independently while proposing practical solutions, rather than only escalating problems.

  • Strong Communication Skills: Maintain ongoing communication and provide regular status updates to the SOC Manager as responsibilities evolve.

  • Strong Technical Skills: The most critical requirement for this role. The ideal candidate is highly technical, possesses strong analytical abilities, and can independently solve complex technical challenges.

  • Critical Thinking and Attention to Detail: Ability to analyze situations thoroughly, challenge assumptions, and focus on details to deliver high-quality outcomes.

On-Call Rotation

  • Participation in the team's on-call  is required as part of this role, including availability to respond to security incidents outside of regular business hours when needed.

Job Details