Senior SOC Platform Engineer (SIEM)
Indexed description
This role is not about building a SOC platform from scratch. Instead, you will focus on expanding data coverage, especially new log sources generated as the company moves its infrastructure to private cloud, standardizing logs using UDM, improving threat detection capabilities, and maintaining and enhancing existing SOC components.
What You Will Do?
- Research, design, and integrate new log sources
- Develop and improve detection rules
- Document the SOC platform
- Build and improve correlation detection
- Maintain and improve existing SOC components
- Evaluate and propose new solutions
- Support Incident Response
Requirements
Must-Have
- 4–5+ years of experience in Security Operations, Security Analysis, or a related security role.
- Hands-on experience operating a SOC environment, including: MITRE ATT&CK, YARA rules, Drools rules, UDM, Apache Flink, Wazuh, ELK, SIEM
- Practical experience with log normalization using UDM (Google SecOps/Chronicle Unified Data Model) or a similar standardized log/data model.
- Good programming and coding skills, with the ability to read, write, integrate, and customize components in a SOC environment, especially UDM, Drools, Flink, and data pipelines.
- Strong debugging and troubleshooting skills, with the ability to independently investigate and resolve production issues involving components such as Falco, Wazuh, Flink, Drools, and TheHive.
- Experience with Public/Private Cloud, Kubernetes, CI/CD, Linux, Kafka, Vector, ELK, ClickHouse, and S3.
- Experience with other open-source tools and technologies in the SOC ecosystem, such as Tetragon, AppArmor, Kyverno, Threat Intelligence, and Threat Hunting.
- Experience training or building custom ML models to improve alert classification, beyond prompt-based approaches.
- Ability to provide technical recommendations and propose improvements to SOC architecture and operational processes.
- Experience designing and fine-tuning LLM prompts for security alert classification and automation, such as identifying True Positive / False Positive alerts.
- We work on large and complex systems, with a focus on ownership and continuous learning.
- We work within existing constraints and improve systems incrementally.
- We value strong fundamentals and the ability to reason through unfamiliar or complex systems.
- Collaboration is direct, and discussions focus on solving problems and delivering results.
- MacBook provided
- Full salary insurance
- Health care insurance
- 19 leave days
- Annual health check-up
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search