Security Operations Analyst (SIEM Operations and Threat Detection)
Core
Enhance threat detection and cybersecurity operations capabilities through security content management, SIEM optimization, and validation of detection mechanisms for complex technology environments.
Role type
Senior Security Operations Analyst (SIEM & Threat Detection)
Builds
Security monitoring, analytics, and detection capabilities across SIEM, EDR, and cloud platforms
Domain
Cybersecurity / Threat Detection / SIEM Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
SIEM administration (Splunk, Microsoft Sentinel), EDR management, cloud security (Azure, AWS, GCP), security content lifecycle management, incident triage, technical threat analysis, security architecture review, metrics and KPI reporting, process optimization, documentation
Preferred skills
SIEM architecture design, cloud monitoring (IaaS/PaaS/SaaS), shell scripting (Python, PowerShell, Bash)
Technologies
Splunk, Microsoft Sentinel, Azure Sentinel, QRadar, ArcSight, ELK Stack, M365, Cloud App Security, Defender for Endpoints, CrowdStrike, AWS, Azure, GCP
Responsibilities
Develop, implement, validate, and tune security monitoring and detection capabilities; onboard and integrate new security data sources; manage security content lifecycle and quality assurance; collaborate with threat intelligence and incident response teams; prepare cybersecurity operations metrics and reports; review and assess detection effectiveness; support CSOC procedure and documentation development
Seniority
Senior, hands-on IC