General description
The person will be member of the global in-house Security Operation Center (SOC team) within Information Security and will:
– · Design, develop and improve threat detection and automation use cases
· Optimize data normalization, correlation, enrichment and threat intelligence integration
· Optimize existing SOC technology stack and architecture as well as DevOps processes.
· Collaborate closely with SOC Engineer peers, SOC Analysts, and SOC Manager for continuous improvement.
· Regularly collaborate with internal and external IT service providers (e.g. new requirements, troubleshooting, …).
Job experience
· Experience as SIEM, SOAR or Threat Detection Engineer (minimum of 5 years)
· SOC experience, ideally with SIEM, SOAR, Threat Detection, and Threat Intelligence areas
Skills
· Strong understanding of threat detection, threat intelligence and security frameworks (e.g. MITRE ATT&CK, Cyber Kill Chain)
· Advanced knowledge in SIEM and SOAR (e.g., Splunk, Cortex), EDR and threat intelligence services
· Good knowledge of data structure from various log sources (e.g. EDR, network, identity, application, cloud, …)
· Strong experience in programming / scripting (e.g. Python) as well as in version control (e.g. GitLab).
Receive emails for the latest jobs matching your search criteria