FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityGoogle Cloud PlatformLinuxPythonRubyShell ScriptingSplunk
About the role
Key responsibilities & impact- Enhance threat detection and cybersecurity operations capabilities within the Cyber Security Operations Center
- Develop, implement, validate, tune and maintain security monitoring, analytics and detection capabilities across SIEM, EDR, cloud and other cybersecurity platforms
- Operate, maintain, optimize and continuously improve security monitoring and threat detection services
- Onboard, integrate, test and validate security data sources, telemetry feeds and monitoring capabilities
- Manage security content, including detection use-case lifecycles, rule reviews, testing, tuning and content quality assurance
- Collaborate with cyber threat intelligence, incident response and cybersecurity operations teams to translate requirements into detection and monitoring capabilities
- Participate in cybersecurity architecture reviews and provide recommendations to improve monitoring and detection effectiveness
- Prepare and maintain cybersecurity operations metrics, dashboards, KPIs and service performance reports
- Review and assess detections, monitoring configurations, operational processes and service deliverables, identifying improvement opportunities
- Analyze operational feedback to optimize tuning, reduce false positives and improve detection quality
- Contribute to quality assurance, process reviews, control validation, service quality assessments and corrective actions
- Maintain CSOC procedures, standards, documentation, knowledge-base articles and operational guidance
- Prepare and present technical reports, summaries, findings and recommendations to internal and external stakeholders
- Participate in the mandatory rotating on-call schedule to resolve critical incidents when required
Requirements
What you’ll need- Mandatory participation in a rotating 24/7 on-call shift schedule from Monday to Sunday; approximately one full week every X months depending on team size
- 5+ years of relevant experience in information technology, including alert triage and security incident support
- Proven experience administering a SIEM platform, preferably Splunk or Microsoft Sentinel SIEM
- Proven experience with SOC tools such as SIEMs and EDRs; ability to independently perform technical analysis of security threats and collaborate with the Incident Response team
- Deep knowledge of Microsoft Security Tools, including M365, Cloud App Security, Azure, Defender for Endpoint, Azure Security, Azure Sentinel and XDR
- Deep knowledge of cloud technologies such as Azure, AWS and GCP
- Deep knowledge of SIEM tools such as Splunk, QRadar, ArcSight, MS Sentinel and ELK Stack
- Knowledge of at least one EDR solution, such as MS Defender for Endpoint or CrowdStrike
- Knowledge of email security, network monitoring and incident response
- Knowledge of Linux, Mac and Windows
- C1 English proficiency
- Experience building SIEM architectures from initial design to implementation, including data ingestion pipelines for diverse cloud and on-premises log sources
- Proven knowledge monitoring AWS environments (IaaS, SaaS, PaaS)
- Knowledge of at least one general-purpose or shell scripting language, such as Ruby, Bash, PowerShell or Python
- Desirable certifications include MCSE, CCNA, Microsoft Azure SC-200, GCIH, CEH, GCFA or any GIAC/similar certification
- Excellent communication skills
- Customer-facing and oral communication experience
- Ability to write documentation and reports
- Creativity and ability to find innovative solutions
- Willingness to learn on the job
- Conflict management and cooperation
Benefits
Comp & perks- Remote position
- Freelance, full-time contract
- Training and career development
- Possibility to be part of a multicultural team and work on international projects
