Security System Engineer
- Джерело:
- djinni.co
Що робити
- Assess the maturity of the security monitoring function (data sources, pipelines, detections, processes, tooling) against industry good practice and the organization's threat landscape. Turn the findings into a prioritized, evidence-based improvement roadmap.
- Own the monitoring architecture: data sources, log pipelines, SIEM/analytics platforms, and their reliability, scalability, and cost. Define standards for log onboarding, normalization, and data quality.
- Design and evolve the detection engineering lifecycle: use-case management, coverage analysis, testing and validation, tuning, and retirement. Build detections from available telemetry and relevant threat scenarios, and measure their effectiveness.
- Use incident investigations and root cause analysis as inputs for systemic improvements to telemetry and detections.
- Automate repetitive monitoring, enrichment, and response tasks, prioritizing by the value they bring to SOC workflows.
Що очікуємо
- 5+ years in cybersecurity, including SOC engineering, SIEM, or detection engineering.
- Deep understanding of SOC operations, detection engineering, incident response, threat intelligence, threat hunting, DFIR, and SOC engineering.
- Hands-on experience with SIEM, EDR/XDR, NDR, threat intelligence platforms, and incident management systems.
- Knowledge of ISO/IEC 27001, MITRE ATT&CK, and SOC maturity models, with experience assessing monitoring maturity and defining a target state and roadmap.
- Solid grasp of monitoring architecture: log collection and processing, data quality, and the trade-offs between visibility, cost, and operational load.
Схожі вакансії
З блогу Trackr
Усі статті →Знайдено через trackr.help/jobs · Канал: @trackrhelp · Бот для персональних сповіщень: @trackrhelpBot


