Role Summary:
We are looking for an experienced SIEM Engineer to join our SOC team. The role involves managing and optimizing SIEM platforms (primarily Microsoft Sentinel, plus Splunk/QRadar/Elastic), developing detection content, automating workflows, and supporting threat hunting and incident response.
Key Responsibilities:
Onboard and normalize log sources (cloud, endpoint, network, SaaS).
Develop and tune detection rules (KQL) mapped to MITRE ATT&CK.;
Build dashboards, health checks, and KPIs.
Implement SOAR automation (Sentinel Playbooks, Logic Apps).
Support threat hunting and assist in incident investigations.
Maintain SIEM performance, cost optimization, and compliance.
Required Skills:
5–8 years in SOC/Threat Detection/Incident Response/SIEM engineering roles.
Solid expertise in Microsoft Sentinel (KQL, analytics rules, hunting, playbooks).
Hands-on with at least one other SIEM (Splunk, QRadar, Elastic).
Knowledge of MITRE ATT&CK;, detection engineering, and log analysis.
Scripting in PowerShell/Python for automation.
Familiarity with EDR, IAM, firewall, and cloud security logs.
Must have SIEM solution implementation experience.
Preferred Certifications:
SC-200 or AZ-500
Splunk/QRadar