Key Responsibilities
Hands-on implementation and administration of at least one SOC/SIEM platform.
Develop, tune, and optimize SIEM use cases, correlation rules, and alerts to reduce false positives and improve detection.
Onboard and troubleshoot security device/log-source integrations with the SOC/SIEM.
Investigate L1-escalated alerts by correlating logs across multiple security controls and perform detailed RCA.
Identify attack vectors, IOCs, affected systems/users, and recommend containment and remediation.
Monitor and investigate security events from Firewall, WAF, DLP, VPN, EDR/XDR, IAM/AD, Cloud and endpoints.
Robust understanding of Firewall L2/L3/L4 concepts including ACL, NAT, routing and VPN.
Positive understanding of L7/WAF security, OWASP Top 10,
web attacks and API security; Cloudflare WAF experience preferred.
Working knowledge of DLP, IAM/AD, AWS/Cloud security and Linux investigation.
Develop and improve detection capabilities based on emerging threats, preferably mapped to MITRE ATT&CK;.
Mandatory Skills
Hands-on SOC/SIEM implementation Mandatory
SIEM use-case/rule optimization – Mandatory
Security device/log-source integration – Mandatory
L2 incident investigation and RCA – Mandatory
Firewall, VPN, DLP and WAF understanding
IAM/AD, Cloud/AWS and Linux knowledge
Robust analytical and troubleshooting skills