Security Operations Platform Engineer
Core
Design, implement, manage, and optimize SIEM/SOAR platforms to support SOC operations, threat detection, and incident response.
Role type
Security Operations Platform Engineer
Builds
SIEM/SOAR platform capabilities for log ingestion, threat detection, and automation
Domain
Information Security / SOC Operations
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM platform management, SOAR platform management, log ingestion and normalization, scripting (Python/PowerShell), SIEM query languages, network protocols, firewall/IDS/IPS/EDR log analysis, MITRE ATT&CK, incident response processes
Preferred skills
SOAR platform management, automation playbook development, cloud log configurations (Azure/AWS/GCP), compliance framework support (NIST/ISO/SOX/HIPAA)
Technologies
SIEM, SOAR, Python, PowerShell, CEF, LEEF, JSON, Azure, AWS, GCP
Responsibilities
Configure and maintain SIEM/SOAR platform, onboard and normalize log sources, build integrations via scripting, develop and tune detection rules and alerting thresholds, build and maintain dashboards for SOC operations and compliance, collaborate with SOC analysts during investigations
Seniority
Mid-level, hands-on IC