SOC Engineer (Managed SOC)
Indexed description
This is a hands-on engineering role focused on designing and maintaining Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), and supporting security technologies. The role owns the end-to-end lifecycle of security monitoring capabilities - from onboarding new log sources and developing detection content to automating operational workflows and continuously enhancing SOC performance - while ensuring solutions align with customer requirements, cybersecurity best practices, and operational standards.
Responsibilities:
SIEM & Security Platform Engineering
- Design, implement, configure, and maintain enterprise SIEM and SOAR platforms supporting ZainTECH's Managed Security Services portfolio.
- Deploy and maintain highly available, scalable, and secure SOC infrastructure across customer environments.
- Manage platform upgrades, patching, configuration management, and lifecycle activities to ensure platform stability and performance.
- Ensure SOC technologies remain aligned with operational, security, and customer requirements
- Develop, maintain, and optimise SIEM detection content, including correlation rules, dashboards, reports, alerts, watchlists, and use cases.
- Improve detection capabilities by analysing emerging threats, attack techniques, and operational trends.
- Reduce false positives through continuous tuning and refinement of detection logic.
- Map detection capabilities to recognised cybersecurity frameworks such as MITRE ATT&CK
- Integrate security technologies, cloud platforms, infrastructure, and third-party solutions into the SIEM ecosystem.
- Develop custom parsers, connectors, and data ingestion mechanisms to support new customer environments.
- Design and implement SOAR playbooks to automate investigation, enrichment, notification, and response activities.
- Optimise data collection, normalisation, and event processing to improve operational efficiency
- Provide technical support to SOC Analysts during security investigations and major incident response activities.
- Troubleshoot platform issues and perform root cause analysis to maintain service availability.
- Produce technical documentation, implementation guides, and operational runbooks.
- Identify opportunities to improve SOC maturity through automation, process optimisation, and engineering best practices.
- Collaborate with Cybersecurity Consulting, Incident Response, Product Management, and Delivery teams to continuously enhance Managed Security Services
- 3-5 years of hands-on experience designing, implementing, and administering SIEM platforms within enterprise or Managed Security Services environments.
- Strong experience with one or more SIEM platforms such as Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, ArcSight, LogRhythm, or Elastic Security.
- Experience integrating multiple security technologies, including EDR, firewalls, IDS/IPS, cloud security platforms, identity platforms, and threat intelligence feeds.
- Working knowledge of Windows, Linux, networking, scripting, APIs, and automation technologies
- Experience implementing SOAR platforms and security automation workflows.
- Knowledge of MITRE ATT&CK, threat intelligence integration, and detection engineering principles.
- Experience supporting enterprise cloud environments including Microsoft Azure, AWS, or Google Cloud Platform.
- Experience working within a Managed Security Services Provider (MSSP) environment
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related field.
- Security +, CEH or any relevant certification preferred
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search