Associate – SIEM/SOAR Engineering
Core
Responding to and mitigating cybersecurity incidents, analyzing security events, and supporting Security Operations Center (SOC) operations to protect client systems and data.
Role type
Associate SIEM/SOAR Engineer
Builds
Incident response workflows, threat detection use cases, and security monitoring capabilities
Domain
Cybersecurity, Security Operations, Cloud Security
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
SIEM platform expertise, SOAR workflow implementation, incident response, vulnerability assessment, digital forensics, threat intelligence, security architecture support, NIST/ATT&CK framework application, cloud security knowledge
Preferred skills
Python scripting, User Entity Behavior Analytics, Machine Learning models, cloud/hybrid environment management, security governance strategy
Technologies
Splunk, ArcSight, Azure Sentinel, Logic Apps, Phantom, Demisto, Azure Security Center, Azure Monitor, Azure Log Analytics, Azure NSG, Azure Functions, Defender ATP
Responsibilities
Responding to and mitigating cybersecurity incidents, Analyzing security incidents to identify vulnerabilities, Collaborating to maintain secure network infrastructure, Implementing threat mitigation strategies, Conducting vulnerability assessments, Engaging in digital forensics investigations, Supporting SOC security architecture development
Seniority
Associate, hands-on IC