Security Operations Engineer
Core
Building and optimizing SIEM detection capabilities, supporting threat verification, and enabling regulatory alignment with DORA requirements.
Role type
Security Operations Engineer (SIEM Detection)
Builds
SIEM detection rules and monitoring capabilities for critical applications
Domain
Financial services / Cybersecurity / Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM platform expertise (Microsoft Sentinel), Detection rule engineering, Scripting (Python, PowerShell, Bash), Cloud infrastructure knowledge (Azure, AWS), OS knowledge (Windows, Linux), Database knowledge (SQL, Oracle), Stakeholder workshop facilitation, Technical documentation
Preferred skills
Threat modelling, Regulatory framework familiarity (DORA)
Technologies
Microsoft Sentinel, Azure, AWS, KQL, Python, PowerShell, Bash
Responsibilities
Design and optimize SIEM detection rules, Develop and execute test cases for detection logic, Support onboarding of critical applications into security monitoring, Collaborate with application teams to define logging requirements, Lead workshops with stakeholders to align on threat scenarios, Produce documentation covering detection logic and threat models
Seniority
Mid-level, hands-on IC