Job Description :
As a highly skilled and motivated Cybersecurity Professional, you will serve as a subject matter expert in our technology stack, optimizing security tools and detection workflows. You will mentor junior analysts on complex investigation techniques and drive continuous improvement initiatives across our multi-client SOC environment.
This role demands advanced analytical skills to conduct in-depth analysis of escalated security incidents from Tier 1 analysts, performing advanced threat investigations to determine attack vectors, assess impact scope, and develop comprehensive remediation strategies.
Key Responsibilities
- General responsibilities :
- Recommend improvements for Standard Operating Procedures (SOPs)
- Propose enhancements on tools and workflow
- Respond in a timely manner to support tickets
- Document actions in tickets to effectively communicate information internally and to customers
- Adhere to policies, procedures, and security best practices
- Take responsibility for customer satisfaction and overall success of managed services
- Be available, ready, and able to accept incoming client calls
- Mentor fellow Security Engineers and Security Analysts
- Service Improvement :
- Optimize SIEM rules and detection logic to reduce false positives and improve detection accuracy
- Support rules factory program in improving the global set of detection
- Validate Go-to-Active and Go-to-Prod gates of our new clients to ensure a smooth transition to operation
- Continuously improve incident templates in terms of content for the clients and in terms of automation to best support the operation
- Support rollout of new set of rules for our clients
- Qualify, analyze, and provide recommendations for new standard data source requests
- Support Product teams to build best new services to fit with Operations capabilities (needs, scalability, efficiency)
- Threat Monitoring :
- Manage escalated cases from T1 Analysts
- Analyze and respond to security events from SIEM, EDR, FWs, IDS, IPS, AV, and other security data sources
- Deliver high-quality Incident Handling and investigation
- Conduct threat hunting activities using advanced analytics and threat intelligence
- Provide 24 / 7 on-call support for critical security incidents outside business hours
As a team player willing to iterate on our internal processes to improve the team's efficiency, you will thrive in an international / global environment. Experience in solving complex problems, being dynamic, and having strong interpersonal and communication skills is essential.
Requirements include :
A minimum of 4 years of hands-on experience in cybersecurity operations, incident response, or threat analysisBachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent experienceProven track record in a SOC and international / global environmentAdvanced proficiency with SIEM platforms (Splunk, QRadar, Sentinel, etc.)Extensive experience with EDR / XDR solutions (CrowdStrike, SentinelOne, Microsoft Defender, etc.)Deep understanding of network security technologies (firewalls, IDS / IPS, network monitoring)Strong knowledge of Windows and Linux / Unix operating systems and forensicsExperience with cloud security (AWS, Azure, GCP) and containerization technologiesFamiliarity with OT / ICS environments and industrial control systems securityProficiency in scripting languages (Python, PowerShell, Bash) for automationUnderstanding of threat intelligence platforms and MITRE ATT&CK frameworkBenefits :
Opportunity to work with talented peersCreative problem-solving and the ability to tackle unique, complex projectsCompetitive compensation with a benefits package that protects you and your loved ones and allows you to pursue career growth with tuition reimbursementGenerous time off for rest, relaxation, and hobbiesColleagues from across the globe who are interested in helping clients protect their companies so they can focus on fulfilling their missionWhy You'll Love It Here :
We have a culture that supports growth, fosters success, and moves the industry forward. With our most comprehensive ecosystem of security products and partners, we deliver unparalleled services to clients of varying sizes and industries, including commercial, government, and education.