Security Operations Engineer
Playtech's Security unit is looking for a Security Operations Engineer with excellent communication and problem-solving skills. This role involves supporting, maintaining, and operating security infrastructure and technologies used by the SOC, and making recommendations to enhance threat detection. The engineer will build and improve real-time security monitoring and incident response frameworks and playbooks, develop security detection use cases, tune signatures, and refine analytical models to identify malicious activity. They will also maintain, tune, and troubleshoot the SIEM Solution for optimal performance and detection capabilities, identify and integrate new data sources into monitoring operations, and evaluate and implement new information security tools and technologies. The role includes providing analysis and trending of security events, alarms, and information from various security devices and critical environments, participating in knowledge sharing, and improving incident response documentation. Additionally, the engineer will provide Incident Response (IR) investigation, support, and triage to security alerts.
- Support, maintain and operate security infrastructure and technologies used by SOC and make recommendations to enhance threat detection
- Build up and improve real-time security monitoring and incident response framework and playbooks
- Develop security detection use cases, tune signatures and refine analytical models in order to identify malicious activity
- Maintain, tune and troubleshoot SIEM Solution to deliver optimal performance and best detection and investigation capabilities
- Identify new data sources and integrate them into monitoring operations
- Evaluate and implement new information security tools and technologies in support of SOC needs
- Provide analysis and trending of security events, alarms, and information from a large number of heterogeneous security devices and critical environments
- Participate in knowledge sharing with other analysts and improve incident response documentation
- Provide Incident Response (IR) investigation, support and triage to security alerts
- Should have 2+ years of experience in a technical environment in the role of Security Operations Engineer/Security Engineer/SRE/DevOps
- Must have ability to identifies and develop workflow automation to lower response time and eliminate lengthy response times
- Display good knowledge of Information Security, IT and Networking principles
- Must have ability to demonstrate a deep understanding of cyber security monitoring platforms such as intrusion detection systems (IDS), Endpoint Protection, Web proxies, firewalls, EDR, UEBA, CASB
- Must have solid organizational skills including attention to detail and multitasking skills.
- Should have great written & spoken English.
- Have experience with Linux, Docker
## You'll get extra points for...
- Basic knowledge of AWS, GIT, CI/CD
- Possibility to work with a product company
- Personalised professional growth
- Warm and friendly attitude to every specialist
- Educational possibilities
- Competitive salary and benefits
- Medical insurance
- Fully-equipped cosy office space located in the city centre (Gulliver, “Palats Sportu” metro station)
- Paid vacation days, sick leaves and national holidays
- Corporate events and team buildings
