Security Operations Engineer
Support, maintain and operate security infrastructure and technologies used by SOC and make recommendations to enhance threat detection. Build up and improve real-time security monitoring and incident response framework and playbooks. Develop security detection use cases, tune signatures and refine analytical models in order to identify malicious activity. Maintain, tune and troubleshoot SIEM Solution to deliver optimal performance and best detection and investigation capabilities. Identify new data sources and integrate them into monitoring operations. Evaluate and implement new information security tools and technologies in support of SOC needs. Provide analysis and trending of security events, alarms, and information from a large number of heterogeneous security devices and critical environments. Participate in knowledge sharing with other analysts and improve incident response documentation. Provide Incident Response (IR) investigation, support and triage to security alerts.
- Support, maintain and operate security infrastructure and technologies used by SOC and make recommendations to enhance threat detection
- Build up and improve real-time security monitoring and incident response framework and playbooks
- Develop security detection use cases, tune signatures and refine analytical models in order to identify malicious activity
- Maintain, tune and troubleshoot SIEM Solution to deliver optimal performance and best detection and investigation capabilities
- Identify new data sources and integrate them into monitoring operations
- Evaluate and implement new information security tools and technologies in support of SOC needs
- Provide analysis and trending of security events, alarms, and information from a large number of heterogeneous security devices and critical environments
- Participate in knowledge sharing with other analysts and improve incident response documentation
- Provide Incident Response (IR) investigation, support and triage to security alerts
- 2+ years of experience in a technical environment in the role of Security Operations Engineer/Security Engineer/SRE/DevOps
- Ability to identify and develop workflow automation to lower response time and eliminate lengthy response times
- Good knowledge of Information Security, IT and Networking principles
- Ability to demonstrate a deep understanding of cyber security monitoring platforms such as intrusion detection systems (IDS), Endpoint Protection, Web proxies, firewalls, EDR, UEBA, CASB
- Solid organizational skills including attention to detail and multitasking skills
- Great written & spoken English
- Experience with Linux, Docker
- Basic knowledge of AWS, GIT, CI/CD
- Possibility to work with a product company
- Personalised professional growth
- Warm and friendly attitude to every specialist
- Educational possibilities
- Competitive salary and benefits
- Medical insurance
- Fully-equipped cosy office space located in the city centre (Gulliver, “Palats Sportu” metro station)
- Paid vacation days, sick leaves and national holidays
- Corporate events and team buildings
