Required SecOps Specialist
About the team:
What will your job look like:
Develop, test, tune, and maintain SIEM detection rules, correlation logic, dashboards, and alert thresholds.
Integrate security tools and services using APIs, webhooks, scripts, and automation platforms.
Analyze logs and telemetry to identify suspicious or malicious activity, assess impact, and determine the appropriate response.
Monitor, triage, and investigate security alerts from SIEM, EDR, cloud, identity, email, and network-security platforms.
Build and enhance SOAR playbooks to automate alert enrichment, investigation, case management, notifications, and approved containment actions.
Validate SIEM data coverage, log quality, parsing, ingestion health, and retention across security-relevant systems.
Collaborate with IT, cloud, infrastructure, identity, network, and engineering teams to contain incidents and drive remediation.
Create and maintain incident-response runbooks, investigation guides, detection documentation, and automation procedures.
Translate investigation findings and post-incident lessons learned into improved detections, automation workflows, and security controls.
Requirements: 1-2 years of hands-on experience in Security Operations, SOC, Cyber Analysis, Incident Response, or Detection Engineering - Must.
Practical experience operating and maintaining SIEM platforms, including log onboarding, parsing, developing and tuning detection rules and alerting use cases - Must
Excellent written and verbal communication skills for documentation and reporting in English.
Experience analyzing security telemetry from different systems such as EDR, Windows and Linux systems, identity services, cloud environments, email-security tools, firewalls, DNS, proxy, VPN, and network devices.
Strong understanding of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework.
Proficiency in SIEM query languages such as KQL or SQL - Advantage
Experience with scripting or automation using Python, PowerShell, Bash, REST APIs, JSON, or webhooks - Advantage.
Familiarity with SOAR platforms and automation workflows for alert enrichment, investigation, case management, and response - Advantage.
This position is open to all candidates.