Job Description
Roles & Responsibilities
Responsible for configuring, maintaining, and supporting CSOC platforms, tools and logging infrastructure ensuring all systems fully operational and secure. Manage the development, customization and tuning of security content, including use cases, rules, and playbooks, to effectively detect and respond to cyber threats, ensuring detection logic and automation workflows align with CSOC priorities and cyber threat intelligence. Designing and build CSOC technologies such as SIEM, SOAR, EDR, and other platforms. Design and develop security content for, SIEM, SOAR and EDR Configure and maintain SIEM, SOAR, EDR, and other CSOC platforms. Build and manage logging infrastructure to ensure full telemetry coverage. Manage log source onboarding, parsing, normalization, data ingestion pipelines, and enrichment activities. Develop, test, and fine-tune detection rules, correlation logic, and alert conditions. Map and report detection coverage against frameworks (e.g., MITRE ATT&CK). Propose new detection ideas based on threat research and attack simulations. Build SOAR playbooks and automation scripts for alert enrichment and incident response. Translate threat intelligence, red team findings, and vulnerability data into use cases. Perform false-positive analysis and rule optimization to improve fidelity. Maintain a content repository with versioning, documentation, and lifecycle status. Work with threat monitoring and DFIR teams to validate use case effectiveness. Maintain system documentation, configuration baselines, and maintenance records. Monitor health and availability of all logging pipelines and tools. Conduct root-cause analysis of tool outages or data loss.
Desired Candidate Profile
- Bachelor's degree in Computer Engineering, Computer Science, Information Technology, or a related field.
- 3-6 years of experience in Cybersecurity Operations (CSOC), Detection Engineering, or Detection Content Development.
- Strong understanding of SOC architecture, security technologies, and log management, including ingestion, parsing, enrichment, correlation, and storage best practices.
- Hands-on experience with the design and implementation of SIEM/SOAR platforms, such as Splunk, ELK, LogRhythm, Microsoft Sentinel, Palo Alto XSIAM, or similar.
- Solid knowledge of network infrastructure, Linux/Windows administration, and system monitoring, with expertise in security telemetry (firewall, EDR, proxy, and other log sources).
- Proficiency in query and scripting languages (e.g., KQL, SPL, Sigma) for automation, detection tuning, and source validation.
- Familiarity with SOAR automation and orchestration tools (e.g., Cortex XSOAR, Sentinel Logic Apps, or Phantom) and experience designing scalable, reusable detection content.
- In-depth understanding of threat detection concepts, attacker behaviors, and MITRE ATT&CK mapping, including content gap analysis and threat model alignment.
- Strong analytical and troubleshooting skills with the ability to ensure high availability and reliability of security tooling.
- Knowledge of AI/ML concepts and their application in cybersecurity for detection and automation use cases.
- Good communication and coordination skills, with the ability to collaborate effectively across teams such as Threat Monitoring, CTI, and DFIR.
- Strong documentation and version control discipline (e.g., Git, Confluence) and attention to detection accuracy and operational impact.
- Understanding of data integrity, retention policies, and relevant regulatory/compliance standards.
- Relevant certifications in SIEM/SOAR/EDR platforms (e.g., Splunk, ELK, LogRhythm, Microsoft Sentinel, Palo Alto XSIAM, or equivalent) are preferred.