Security Monitoring: Perform continuous monitoring and triage of security events and alerts generated by SIEM, EDR, NDR, IDS/IPS, firewalls, and cloud security environments.
Incident Investigation & Triage: Investigate suspected cybersecurity alerts, conduct root-cause analysis, and initiate incident response playbooks for containment, eradication, and recovery.
Threat Hunting & Intelligence: Actively hunt for hidden adversaries, analyze indicators of compromise (IOCs), and integrate real-time threat intelligence feeds into detection systems.
Detection Engineering: Create, maintain, and test security monitoring use cases, detection rules, and automated SOAR response playbooks.
Reporting & Drills: Prepare detailed incident reports, compile operational security metrics for dashboards, and actively participate in cyber simulation drills and forensics.
Job Requirements
Bachelor's degree in Computer Engineering, Information Security, or a related field.
3+ years of experience working within an enterprise Security Operations Center (SOC).
Hands-on experience configuring and analyzing SIEM logs (Splunk, QRadar, Microsoft Sentinel, etc.), EDR solutions, and firewall rule behaviors.
Solid understanding of network protocols, operating system forensics (Windows/Linux), and the MITRE ATT&CK framework.
Strong analytical, problem-solving, and script writing skills (Python, Bash, or PowerShell).