SOC Detection and Response - Engineer Cyber Security Engineer
Core
Monitor, triage, and investigate security alerts from SIEM, EDR, and cloud platforms to identify and contain threats.
Role type
SOC Detection and Response Engineer
Builds
Security monitoring workflows, incident response outcomes, and detection quality improvements
Domain
Cybersecurity, Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM platforms, EDR platforms, network security fundamentals, MITRE ATT&CK frameworks, cloud security concepts, incident response procedures, alert triage, evidence collection, documentation
Preferred skills
SOAR platforms, threat hunting, digital forensics, malware analysis, Python scripting, PowerShell, Bash
Technologies
Splunk, CrowdStrike Falcon, Microsoft Defender, Google SecOps
Responsibilities
Monitor and triage security alerts from SIEM, EDR, IDS/IPS, and cloud security platforms; Perform initial investigation and enrichment to determine alert validity and business impact; Analyze endpoint, network, identity, and cloud telemetry to identify indicators of compromise; Escalate complex or confirmed security incidents to senior analysts; Assist with containment and response activities; Support maintenance and testing of security automation workflows and SOAR playbooks; Maintain accurate documentation of investigations and incident response actions
Seniority
Mid-level, hands-on IC