SOC Engineer / Detection Engineer
As a SOC Engineer / Detection Engineer, you will be responsible for detecting, investigating, and responding to security incidents across our environment, while continuously improving how we detect and handle threats. You will work hands-on with our SIEM and incident response processes, and act as a key point of contact between the SOC and other engineering/security teams.
Depending on your profile, some of your responsibilities can include:
- Incident Response: Lead and support the end-to-end response to security incidents, from detection through containment, eradication, and recovery.
- Security Investigation: Conduct in-depth investigations into suspicious activity and alerts, correlating data across logs, endpoints, network, and cloud sources to determine root cause and impact.
- Post-Mortems & RCAs: Drive post-incident reviews and root cause analyses (RCAs), documenting timelines, findings, and actionable follow-ups.
- SIEM Engineering: Implement, tune, and maintain SIEM use cases, detection rules, correlation logic, and alerting to reduce false positives and close detection gaps.
- SIEM Support: Provide ongoing support for the SIEM platform, including onboarding new log sources, troubleshooting data ingestion, and maintaining dashboards/reports.
- Cross-Team Collaboration: Partner with Engineering, IT, and other Security teams to remediate findings, validate fixes, and share threat context.
- Process Improvement: Identify gaps in detection, response, and documentation, and drive improvements to playbooks, runbooks, and SOC workflows.
**Must have:**
- Incident Response: Hands-on experience handling security incidents, including triage, containment, and coordination across teams.
- Investigation Skills: Strong analytical ability to investigate alerts and logs (SIEM, EDR, network, cloud) and determine root cause.
- SIEM Expertise: Practical experience implementing and tuning detection rules/use cases in a SIEM (e.g., Splunk, Sentinel, Elastic, QRadar).
- RCA & Documentation: Proven ability to write clear post-mortems, RCAs, and incident reports for both technical and non-technical audiences.
- Communication: Ability to work cross-functionally with engineering and other security teams, translating findings into clear remediation steps.
- Process Mindset: Track record of identifying and driving improvements to detection and response processes.
- Linux/Unix proficiency and comfort working across cloud (e.g., AWS) log sources.
**Nice to have:**
- Experience with detection engineering frameworks (e.g., MITRE ATT&CK) to map and prioritize coverage.
- Familiarity with scripting/automation (Python, etc.) for detection or response tasks.
- Understanding of compliance frameworks (ISO 27001, NIST, SOC2) as they relate to incident response.
- Relevant certifications (e.g., GCIH, GCFA, Security+, SC-200, or SIEM-specific certifications).