← Усі вакансії

Security System Engineer

Джерело:
djinni.co
Відгукнутись на вакансію →

Що робити

  • Assess the maturity of the security monitoring function (data sources, pipelines, detections, processes, tooling) against industry good practice and the organization's threat landscape. Turn the findings into a prioritized, evidence-based improvement roadmap.
  • Own the monitoring architecture: data sources, log pipelines, SIEM/analytics platforms, and their reliability, scalability, and cost. Define standards for log onboarding, normalization, and data quality.
  • Design and evolve the detection engineering lifecycle: use-case management, coverage analysis, testing and validation, tuning, and retirement. Build detections from available telemetry and relevant threat scenarios, and measure their effectiveness.
  • Use incident investigations and root cause analysis as inputs for systemic improvements to telemetry and detections.
  • Automate repetitive monitoring, enrichment, and response tasks, prioritizing by the value they bring to SOC workflows.

Що очікуємо

  • 5+ years in cybersecurity, including SOC engineering, SIEM, or detection engineering.
  • Deep understanding of SOC operations, detection engineering, incident response, threat intelligence, threat hunting, DFIR, and SOC engineering.
  • Hands-on experience with SIEM, EDR/XDR, NDR, threat intelligence platforms, and incident management systems.
  • Knowledge of ISO/IEC 27001, MITRE ATT&CK, and SOC maturity models, with experience assessing monitoring maturity and defining a target state and roadmap.
  • Solid grasp of monitoring architecture: log collection and processing, data quality, and the trade-offs between visibility, cost, and operational load.

Схожі вакансії

З блогу Trackr

Усі статті →

Знайдено через trackr.help/jobs · Канал: @trackrhelp · Бот для персональних сповіщень: @trackrhelpBot