Its a role for someone with a deep curiosity for cybersecurity, a proactive mindset, and a desire to improve enterprise security at scale. If youre motivated by continuous learning and thrive in fast- paced environments, wed love to talk to you.
How You Will Make an Impact
Act as a senior member of the Security Operations Center (SOC), independently handling and resolving incidents, while driving lessons learned and continuous improvement.
Collaborate with global teams and develop best practices around processes, tools, and awareness.
Perform in-depth analysis of complex security logs, SIEM events, and correlated data to identify, assess, and remediate threats.
Maintain and improve existing security tools, create and refine use cases, and tailor configurations based on evolving threat intelligence.
- Conduct penetration testing, vulnerability assessments, and guide remediation efforts.
- Take a proactive approach to identifying risks, potential issues, and opportunities for improving the security posture of the organization.
- Contribute to 24/7 SOC capabilities, ensuring effective detection and response coverage.
- Participate in compliance and audit-related efforts by helping ensure system and policy adherence.
- Support SOAR platform integration and automation to improve incident response workflows.
- Mentor junior team members and promote a strong, collaborative team culture.
What You Will Bring to The Table
- 4-5+ years in Information Security or related cybersecurity roles.
Hands-on experience in a SOC environment, with deep exposure to SIEM and endpoint/network security.
2+ years of experience with cloud environments and cloud-native security tools.
Experience with SOAR platforms and scripting (Python, PowerShell, Bash, etc.).
- Experience with penetration testing, vulnerability scanning, and vulnerability management processes.
Working knowledge of Linux systems and syslog analysis from CLI.
2-4 years of systems analysis and incident handling.
Strong grasp of cloud security concepts such as access control, data protection, threat detection, and compliance monitoring.
Tools & Technologies:
Azure Sentinel, QRadar, Splunk
Cisco IDS/IPS, Palo Alto, McAfee Security Suite
Tenable Nessus, ForeScout, Cisco ISE
Comfortable with query languages such as KQL or SQL (considered an advantage).
Operational knowledge of APIs is a plus.