Security Monitoring Analyst
Indexed description
As a Job Title, Your Main Objective Is To
We believe the best person to write a detection rule is someone who knows exactly how to bypass it.
We are looking for an experienced Red Teamer who wants to pivot into our primary Detection Strategist. You will own the quality and direction of our detection logic: assess our telemetry and logging posture, identify visibility gaps, define detection requirements, and author high-fidelity detection content that holds up against real-world bypass techniques.
You will be the connective tissue between offensive tradecraft and SOC outcomes—translating attacker behavior into durable, actionable detections.
Main missions
Your main responsibility is to ensure that when an adversary moves, we see it. You will spend most of your time inside our SIEM, crafting high-fidelity alerts based on your knowledge of offensive TTPs.
Your Responsibilities Include
- Logic Creation: You will author complex KQL queries to detect sophisticated behaviors (e.g., Token manipulation, C2 jitter, etc.) rather than simple IOC matching.
- Telemetry Analysis: You will deeply analyze raw logs from EDR, Identity Providers, and Cloud infrastructure to determine what data is missing and work to enable the right logging policies.
- False Positive Reduction: You will apply your knowledge of "normal" vs. "malicious" administrative behavior to tune existing rules, ensuring the SOC is not flooded with noise.
You will still get your hands on the keyboard to attack, but the goal is different. you are generating data.
- Validation Attacks: You will execute specific, manual attack sequences to verify that a new detection rule triggers.
- Gap Analysis: You will simulate specific techniques (mapped to MITRE ATT&CK) to prove where our blind spots are, then immediately switch gears to fix them.
- Review and optimize the current library of detection rules for accuracy and coverage.
- Collaborate with the Incident Response team to understand why previous attacks were missed and engineer rules to prevent recurrence.
About The Entity
AXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
- State-of-the-art Data Technology to drive customer experience
- State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
- High-Performing Global Team for stronger partnerships with AXA entities
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search