Cyber Security Engineer II
Core
Design, build, and maintain advanced detection rules within SIEM/XDR environments; orchestrate automated response playbooks in SOAR to move the SOC beyond reactive alerting.
Role type
Senior SOC Detection & Orchestration Engineer
Builds
High-fidelity correlation rules, automated response playbooks, and proactive threat hunting capabilities
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM/XDR platform mastery, cloud security monitoring, query languages (KQL, SPL, Lucene), scripting (Python, PowerShell), MITRE ATT&CK framework mapping, forensic analysis, incident leadership
Preferred skills
Advanced threat hunting, telemetry health auditing, post-incident root cause analysis
Technologies
Splunk ES, Microsoft Sentinel, Google Chronicle, Palo Alto Cortex XDR, AWS, Azure, GCP
Responsibilities
Design and maintain advanced detection rules correlating Identity, Network, Cloud, and Endpoint data; Develop and maintain automated response playbooks for incident handling; Lead hypothesis-based threat hunting engagements; Act as Tier 2 escalation point for high-priority incidents; Conduct post-incident reviews to identify systemic weaknesses
Seniority
Senior, hands-on IC