SIEM Content Engineer
Core
Design, configure, and optimize XDR/SIEM/SOAR solutions (IBM, Microsoft, Palo Alto) to detect, analyze, and respond to cyber threats across on-prem and cloud environments.
Role type
Senior IC SIEM Content Engineer
Builds
Detection rules, dashboards, workbooks, notebooks, and incident response playbooks for XDR/SIEM/SOAR platforms
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Python, Bash, PowerShell, MITRE ATT&CK framework, log analysis, networking, operating systems, data normalization, query languages (KQL/AQL/XQL)
Preferred skills
CISSP, CISM, GIAC, project management, threat actor TTPs
Technologies
IBM, Microsoft, Palo Alto, XDR, SIEM, SOAR, KQL, AQL, XQL
Responsibilities
Develop use cases and building blocks for XDR/SIEM/SOAR; Design and configure detection rules and dashboards; Manage threat detection rules; Develop incident management playbooks; Integrate content with various platforms; Monitor and analyze content performance metrics
Seniority
Senior, hands-on IC