SOC Detection Engineer – Senior

Remote senior 23 days ago full-time
Apply now →

✓ Drop your CV once, then continue to the employer's application form. Your profile stays here for every recruiter hiring on igamingjobs.

Role in brief

SOFTSWISS is seeking a Senior SOC Detection Engineer to strengthen security detection across various environments. This role involves developing detection rules and collaborating with multiple teams. Ideal candidates have experience in SOC, detection engineering, and threat hunting.

SplunkMITRE ATT&CKPythonPowerShellBashGitCI/CD

About the role

In this role, you will be part of the Security Operations team at SOFTSWISS, focusing on enhancing the company's ability to identify and respond to security threats. You will develop and maintain detection rules within Splunk or a similar SIEM, ensuring robust coverage across Windows, Linux, and Kubernetes environments.

Your responsibilities will include translating incident investigations into effective detections, analyzing detection gaps, and improving overall detection capabilities. Collaboration with various teams such as Incident Response and Threat Intelligence will be essential to drive security initiatives.

Skills that matter here

  • Splunk: You will utilize Splunk for developing and optimizing detection and correlation rules.
  • MITRE ATT&CK: Understanding MITRE ATT&CK will help you map detections to known attack techniques.
  • Python: Python will be used for automation tasks and enhancing detection processes.
  • PowerShell: You will leverage PowerShell for scripting and automation in security monitoring.
  • Bash: Bash scripting will assist in automating detection and response tasks.
  • CI/CD: You will contribute to CI/CD workflows to improve detection testing and deployment.

Who this role suits

  • Candidates should have a strong background in SOC or detection engineering.
  • A proactive problem-solving attitude is essential for independent investigation of complex issues.
  • Effective communication skills are necessary for collaboration across teams.
  • Experience with security research or participation in the broader security community is advantageous.

From the employer

  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.
  • Translate incident investigations, threat hunting, and attack research into effective detections.
  • Analyze false positives, false negatives, and detection gaps.
  • Improve detection coverage and map detections to MITRE ATT&CK techniques.
  • Develop and optimize SPL queries, dashboards, reports, and risk-based detections.
  • Define requirements for logging, parsing, normalization, enrichment, and data quality.
  • Develop monitoring and health checks for detection rules and data sources.
  • Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.
  • Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.
  • Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.
  • Document detection logic, data sources, dependencies, limitations, and expected behavior.
  • Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.
  • Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.
  • Strong proficiency in Splunk SPL or another enterprise SIEM platform.
  • Experience developing complex queries, correlations, dashboards, and reports.
  • Practical experience tuning detections and managing exceptions and allowlists.
  • Ability to define and evaluate logging and telemetry requirements.
  • Proficiency in Python, PowerShell, or Bash for automation.
  • Experience with Git, code reviews, APIs, and basic CI/CD practices.
  • Understanding of Windows and Linux security monitoring.
  • Ability to independently investigate complex problems and drive solutions to completion.
  • Strong communication skills and the ability to work effectively across teams.
  • Nice to have: Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.
  • Experience with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.
  • Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.
  • Experience building detection quality metrics and automated validation frameworks.
  • Experience with Terraform, Ansible, or other infrastructure-as-code tools.
  • Participation in security research, conferences, or the broader security community.
  • Private health insurance
  • Sports benefits
  • Comprehensive Mental Health Program
  • Free English lessons (online)
  • Local language courses
  • Paid time off
  • Maternity leave support
  • Referral program rewards
  • Upskilling, internal workshops, and participation in professional conferences and corporate events.

Questions about this role

What is the remote policy?

This position is fully remote.

What level of experience is required?

This is a senior-level position requiring strong hands-on experience in SOC and detection engineering.

How can I apply for this position?

You can apply through the SOFTSWISS website at https://www.softswiss.com.

Apply now →

✓ Drop your CV once, then continue to the employer's application form. Your profile stays here for every recruiter hiring on igamingjobs.

Similar jobs