Cyber Security Engineer (SIEM/SOAR)
Indexed description
You will work closely with security operations, threat analysts, and IT teams to improve threat detection, automate response workflows, and enhance overall security operations.
Key Responsibilities
SIEM Administration & Engineering
- Design, implement, configure, and optimize SIEM platforms.
- Develop and maintain correlation rules, dashboards, alerts, and reports for security monitoring.
- Integrate logs and telemetry from networks, endpoints, cloud platforms, and applications.
- Optimize data ingestion, parsing, and normalization to improve detection accuracy and platform performance.
- Monitor and continuously enhance SIEM effectiveness through tuning and rule optimization.
- Implement and administer SOAR solutions.
- Design and develop automated incident response playbooks.
- Automate alert triage, threat intelligence enrichment, and security workflows.
- Integrate SOAR with ticketing systems, security tools, and threat intelligence platforms.
- Partner with security operations teams to reduce manual effort and improve response times.
- Support incident response activities by developing actionable detections and automation.
- Perform root cause analysis on recurring security incidents and implement preventive improvements.
- Assist with maintaining security controls that align with compliance and regulatory requirements.
- Create technical documentation and provide knowledge sharing to security and IT teams.
- Participate in continuous improvement initiatives for security monitoring and response capabilities.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related field.
- At least 5 years of experience in SIEM and/or SOAR administration, engineering, or security operations.
- Experience working in a Security Operations Center (SOC) environment is an advantage.
- Hands-on experience with one or more enterprise SIEM platforms.
- Experience implementing and managing SOAR solutions, including automation playbook development.
- Proficiency in scripting or automation using Python, PowerShell, Bash, or similar languages.
- Strong understanding of cybersecurity frameworks such as MITRE ATT&CK, NIST, and CIS Controls.
- Experience with endpoint security, network security technologies, threat intelligence platforms, and cloud security environments.
- Familiarity with AWS, Microsoft Azure, or Google Cloud security services is an advantage.
- Strong analytical and problem-solving abilities.
- Excellent written and verbal communication skills.
- Ability to work independently while collaborating effectively with cross-functional teams.
- Strong documentation and process improvement skills.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search