Role 1: SIEM/SOC Analyst (SME)
Position Overview: This role requires a technical expert with hands-on
experience in implementing, monitoring, and managing SIEM/SOAR
settings to drive effective incident response.
Key Responsibilities:
SIEM/SOAR Implementation & Operations: Install, configure, and
manage the Seceon SIEM/SOAR primary platform. You will also be
responsible for configuring log ingestion, data pipelines, storage,
alerting, and dashboards.
Detection Engineering: Develop and maintain detection logic,
correlation rules, and use cases. A critical part of the role is
continuously improving detection accuracy and reducing false
positives.
SOC Operations: Perform alert triage and deep investigations. You
will execute playbooks and utilize SOAR to automate responses.
Threat & Vulnerability Management: Conduct threat detection,
vulnerability assessments,
and remediation tracking. You will also
integrate threat intelligence into existing detection workflows.
Security Tool Integration: Integrate the SIEM with IAM solutions,
ticketing tools, and endpoint security (EDR/XDR), including tools
like Defender for Servers.
Required Skills & Experience:
Hands-on experience with SIEM/SOAR tools (Seceon preferred), log
analysis, and incident response.
Familiarity with the security stacks of Fortinet, Trend Micro,
and Microsoft Defender/Sentinel.
Solid analytical thinking and the ability to work in a 24x7 SOC
setting if required.
Basic knowledge of offensive security concepts and security
frameworks.