Cyber Security Engineer
Core
Security Engineer responsible for monitoring, triaging, and responding to security alerts within a Security Operations Centre (SOC), focusing on Splunk log onboarding, detection engineering, and incident investigation.
Role type
SOC Security Engineer (Detection & Response)
Builds
Splunk detection logic, dashboards, and alerting mechanisms
Domain
Cyber Security / SOC Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
Splunk log onboarding, detection engineering, security monitoring, incident triage, MITRE ATT&CK framework, firewall/IDS/IPS configuration, cloud security platforms
Preferred skills
SOAR platforms, security automation, AWS/Azure/GCP environments, Splunk certifications, CompTIA Security+/CySA+
Technologies
Splunk, MITRE ATT&CK, firewalls, IDS/IPS, endpoint detection tools, cloud security platforms
Responsibilities
Monitor, triage, investigate, and respond to security alerts and incidents; onboard and integrate new log sources into Splunk; develop and optimize Splunk searches and detection logic; investigate security events and escalate incidents; contribute to SOC process improvements; collaborate with engineering teams to improve log coverage
Seniority
Mid-level (18 months to 4 years experience)