SOC L2/L3 Engineer
Core
Build and operationalize a SIEM from PoC to production, design detection rules mapped to MITRE ATT&CK, triage L2/L3 alerts, and lead incident response for a payments orchestration platform.
Role type
SOC L2/L3 Engineer (Detection & Response)
Builds
SIEM, detection rules, incident response playbooks, and automated telemetry processing pipelines
Domain
Fintech / Payments Orchestration / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM operation and tuning, MITRE ATT&CK mapping, KQL/SPL query languages, cloud log investigation (AWS, Google Workspace, EDR/XDR), Python scripting, threat hunting, incident response, runbook creation
Preferred skills
SOAR implementation, detection-as-code, UEBA, threat intelligence enrichment, purple teaming, payment-specific environment knowledge (CDE, SWIFT, PCI DSS)
Technologies
SIEM, SOAR, AWS CloudTrail, GuardDuty, Google Workspace, JumpCloud, CDE, SWIFT
Responsibilities
Build and operationalize the SIEM from PoC to production; Design, write, and tune detection rules mapped to MITRE ATT&CK; Triage and investigate L2/L3 alerts; Lead incident response and basic forensics; Onboard log sources across AWS, JumpCloud, Google Workspace, CDE, and SWIFT; Run threat hunts based on realistic attack hypotheses
Seniority
Mid-level, hands-on IC