SOC Engineer
Core
Building and tuning security detections, operating SIEM/SOAR platforms, and conducting cyber investigations to protect digital assets and cloud infrastructure.
Role type
SOC Engineer (Detection Engineering & Incident Response)
Builds
Security detections, incident response playbooks, and threat hunting capabilities for a global mobility group.
Domain
Cybersecurity, Cloud Security, SIEM/SOAR
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Log analysis, correlation, detection engineering, SIEM/SOAR operations, incident investigation, threat hunting, vulnerability correlation, security controls validation
Preferred skills
Cloud security (AWS/GCP), API security, microservices architecture, IAM flows, container security, red-team collaboration
Technologies
Splunk, SOAR (n8n), EDR/XDR, Dynatrace, GitLab, AWS, GCP
Responsibilities
Develop and maintain detection rules, dashboards, and alerts within SIEM/SOAR tools; Perform L3 investigation of security alerts including anomalous authentication and cloud misconfigurations; Conduct proactive threat hunts using log patterns and threat intel feeds; Ensure complete logging coverage across cybersecurity tools, APIs, and cloud workloads; Support vulnerability management by correlating findings with real activity logs; Validate enforcement of cybersecurity standards such as Zero Trust and MFA
Seniority
Mid-Senior, hands-on IC