Security Operations Analyst – Detection Engineering & Threat Hunting
Core
Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry; conduct threat hunts; design SOAR playbooks; and monitor security alerts to reduce false positives.
Role type
Detection Engineering & Threat Hunting Analyst
Builds
Detection logic, SOAR playbooks, and automation workflows for the global SOC
Domain
Cybersecurity, Threat Intelligence, SOC Operations
Required skills
SIEM platforms (Splunk, Chronicle, Elastic), EDR tools (SentinelOne, CrowdStrike), detection logic (Sigma, EQL, KQL, YARA), MITRE ATT&CK frameworks, Python scripting, log investigation (identity, endpoint, cloud, network)
Preferred skills
SOAR platforms, detection-as-code pipelines (GitOps, CI/CD), threat hunt frameworks, purple team exercises, red teaming, penetration testing, malware analysis, digital forensics
Technologies
Splunk, Chronicle, Elastic, SentinelOne, CrowdStrike, Python, PowerShell, Sigma, EQL, KQL, YARA, MITRE ATT&CK
Responsibilities
Monitor security alerts from SIEM, IDS/IPS, firewalls, and EDR systems; Build and tune detections across endpoint, identity, cloud, and SaaS; Reduce alert fatigue via severity tagging and enrichment; Conduct threat hunts based on TTPs and intelligence; Design and maintain SOAR playbooks; Partner with CTI to operationalize threat intelligence; Contribute scripts for investigation efficiency; Support global SOC shift workflows; Assist in post-incident reviews.
Seniority
Mid-level, hands-on IC