We are looking for an experienced SIEM Engineer to join our SOC team. The role involves managing and optimizing SIEM platforms (primarily Microsoft Sentinel, plus Splunk/QRadar/Elastic), developing detection content, automating workflows, and supporting threat hunting and incident response.
#Key Responsibilities:
- Onboard and normalize log sources (cloud, endpoint, network, SaaS).
- Develop and tune detection rules (KQL) mapped to MITRE ATT&CK.;
- Build dashboards, health checks, and KPIs.
- Implement SOAR automation (Sentinel Playbooks, Logic Apps).
- Support threat hunting and assist in incident investigations.
- Maintain SIEM performance, cost optimization, and compliance.
#Required Skills:
- 5–8 years in SOC/Threat Detection/Incident Response/SIEM engineering roles.
- Robust expertise in Microsoft Sentinel (KQL, analytics rules, hunting, playbooks).
- Hands-on with at least one other SIEM (Splunk, QRadar, Elastic).
- Knowledge of MITRE ATT&CK;, detection engineering, and log analysis.
- Scripting in PowerShell/Python for automation.
- Familiarity with EDR, IAM, firewall, and cloud security logs.
- Must have SIEM solution implementation experience.