Senior Information Security Engineer
Core
Senior technical and leadership role driving advanced threat detection, deep-dive investigation, and major cyber incident response within a global SaaS Security Operations Center (SOC), while leading SOC transformation and maturity initiatives.
Role type
Senior IC Information Security Engineer (SOC Lead)
Builds
Detection engineering, automation playbooks, SOC tooling, and incident response capabilities for a global SaaS estate.
Domain
Cybersecurity / SOC Operations / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Major incident response leadership, SOC transformation, detection engineering, threat hunting, forensics, SIEM tuning, automation/SOAR, vulnerability management, mentorship, stakeholder communication
Preferred skills
KQL analysis, Python scripting, threat intelligence platforms, MITRE ATT&CK frameworks, cloud security (Azure/AWS), AI-enhanced detection
Technologies
Microsoft Sentinel, Microsoft Defender for Endpoint, SOAR platforms, SIEM, EDR, Azure, AWS
Responsibilities
Lead end-to-end response to high-priority cyber incidents; perform advanced forensic analysis and root-cause assessment; design and deliver SOC maturity and transformation initiatives; build and tune SIEM detection logic and alerting rules; conduct intelligence-led threat hunts; champion automation and AI-assisted tooling; support vulnerability scanning and risk-based prioritization; create and improve incident runbooks; mentor Tier 1/2 analysts; contribute to SOC KPI reporting and audit readiness; maintain proficiency across SOC tooling and contribute to tooling strategy.
Seniority
Senior, hands-on IC with leadership mandate