HamburgerMenu
hirist

Job Description

What You'll Do :

Security Operations & Incident Response :

- Monitor, triage, and respond to security alerts generated by SIEM platforms (Datadog, Microsoft Defender) and other detection tooling.

- Lead investigations into security incidents and breaches, conducting thorough root-cause analysis and recommending appropriate remediation actions.

- Develop, refine, and execute incident response playbooks to ensure timely containment and resolution of cyber threats.

- Perform threat hunting activities to proactively identify indicators of compromise (IOCs) across cloud and on-premise environments.

- Continuously optimize threat detection capabilities through tuning of EDR, IDS/IPS, firewall rules, and SIEM correlation rules.

Vulnerability & Risk Management :

- Identify, assess, and prioritize vulnerabilities across internal and external applications, systems, and services using VM tools and best-practice methodologies.

- Conduct security assessments and provide remediation guidance in line with industry frameworks (NIST, ISO 27001, CIS).

- Contribute to threat modeling activities for the company's diverse cloud environments (AWS/Azure/GCP).

- Act as a security consultant to cross-functional teams, providing guidance across all domains of information security and risk management.

Cloud & Infrastructure Security :

- Apply deep expertise in AWS and Azure security services (IAM, Security Hub, Defender for Cloud, GuardDuty) to secure cloud-native and hybrid architectures.

- Collaborate with security engineering and IT teams to ensure effective integration and configuration of SOC technologies, including SIEM, EDR, IDS/IPS, firewalls, and vulnerability management tools.

- Engage with partners to secure cloud offerings based on industry best and standard practices.

Compliance & Governance :

- Support SOC 2 and ISO 27001 audit activities, ensuring adherence to compliance standards and facilitating external audits.

- Maintain working knowledge of regulatory requirements (GDPR, HIPAA, PCI-DSS) and apply them to operational security controls.

- Contribute to the development and maintenance of security standards, guidelines, policies, and documentation.

- Collaborate with the GRC (Governance, Risk, and Compliance) function to drive a cohesive security program.

Reporting & Stakeholder Communication :

- Prepare reports and presentations for senior management detailing the current security landscape, recent incidents, and their resolution.

- Manage and report on periodic KPIs and SLA adherence related to SOC operations and platform performance.

- Participate in project and scrum planning prioritization alongside the broader security team.

- Mentor junior analysts and contribute to improving team knowledge through knowledge sharing and hands-on training.

Who You Are :

Experience :


- 10-12 years of relevant technical experience in information security, with at least 5 years in a SOC or security operations role.

- Demonstrated hands-on experience with security tools : SIEM (Datadog, Splunk, Microsoft Sentinel), EDR, IDS/IPS, and vulnerability management platforms.

- Proven experience troubleshooting and responding to security events and incidents in cloud environments.

- Hands-on experience supporting security audits (SOC 2, ISO 27001) and working with external auditors.

Technical Skills :

- Strong hands-on AWS security depth (IAM, Security Hub, GuardDuty) and Azure security depth (Defender for Cloud, Sentinel/Defender).

- Strong Kubernetes and container security experience (cluster hardening, workload identity, runtime controls, image scanning).

- Proven Security Operations automation : triage and response automation, detection engineering, and playbook automation (SOAR/workflows/scripts).

- Strong hands-on Datadog (SIEM/security monitoring), dashboards, alert tuning, and investigation workflows; Splunk/Sentinel familiarity a plus.

- Practical AI/ML skills for SecOps (alert enrichment, correlation, anomaly detection, summarization) and responsible use of AI tools to improve analyst productivity.

- Strong Google Workspace security administration and identity protections (admin controls, audit logs, OAuth app governance).

- Vulnerability management expertise end-to-end (asset discovery, prioritization, remediation verification) and risk-based reporting.

- Strong understanding of networking concepts : VPN, DNS, Routing, Firewalls, and Load Balancing.

- Working knowledge of access control, directory services, and authentication protocols (OAuth, SAML, OpenID).

- Scripting skills in Bash, Python, Terraform, AWS CloudFormation, and API/REST integrations are a strong plus.

- Strong Palo Alto firewall knowledge (policy design, threat prevention, logging, troubleshooting) is a plus.

Education & Certifications :

- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).

- One or more professional certifications preferred : CISSP, CISM, CompTIA Security+, GCIA, GCIH, or equivalent offensive security certifications.

Soft Skills :

- Strong problem-solving skills, attention to detail, and a self-learning mindset.

- Excellent communication skills.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...