Tasks:
- * Assess and deploy security tool updates
- * Build and optimize security detections
- * Deliver engineering backlog improvements
- * Develop CI/CD pipelines for detections and playbooks
- * Document and quality-check engineering changes
- * Engineer SOAR automations and integrations
- * Improve detections and analyst workflows
- * Maintain SIEM, SOAR, EDR, email, and network security controls
- * Manage tooling incidents with vendors and internal teams
- * Onboard and normalize SIEM log sources
- * Support incident investigations with telemetry and detection enhancements
Perks/Benefits:
- + Flexible working
- + Professional development support
- + Wellbeing support
Skills/Tech stack required:
[AWS] [Azure DevOps] [Bash] [CI/CD] [Detection-as-code] [EDR] [Email Security] [GitHub Actions] [Incident Response] [Infrastructure as Code] [JavaScript] [JSON] [Kusto Query] [Kusto Query Language] [Kusto Query Language (KQL)] [Log normalization] [Log onboarding] [Microsoft Azure] [Microsoft Sentinel] [Network detection] [Powershell] [Python] [Security Automation] [Security telemetry] [SIEM] [SOAR] [YAML]
Educational requirements:
N/A
Role(s):
[Automation Engineer] [Cybersecurity Engineer] [Detection Engineer] [Engineer] [Operations Engineer] [Security] [Security Automation Engineer] [Security Operations] [Security Operations Engineer]