Posted on: 19/06/2026
What You'll Do :
Security Operations & Incident Response :
- Monitor, triage, and respond to security alerts generated by SIEM platforms (Datadog, Microsoft Defender) and other detection tooling.
- Lead investigations into security incidents and breaches, conducting thorough root-cause analysis and recommending appropriate remediation actions.
- Develop, refine, and execute incident response playbooks to ensure timely containment and resolution of cyber threats.
- Perform threat hunting activities to proactively identify indicators of compromise (IOCs) across cloud and on-premise environments.
- Continuously optimize threat detection capabilities through tuning of EDR, IDS/IPS, firewall rules, and SIEM correlation rules.
Vulnerability & Risk Management :
- Identify, assess, and prioritize vulnerabilities across internal and external applications, systems, and services using VM tools and best-practice methodologies.
- Conduct security assessments and provide remediation guidance in line with industry frameworks (NIST, ISO 27001, CIS).
- Contribute to threat modeling activities for the company's diverse cloud environments (AWS/Azure/GCP).
- Act as a security consultant to cross-functional teams, providing guidance across all domains of information security and risk management.
Cloud & Infrastructure Security :
- Apply deep expertise in AWS and Azure security services (IAM, Security Hub, Defender for Cloud, GuardDuty) to secure cloud-native and hybrid architectures.
- Collaborate with security engineering and IT teams to ensure effective integration and configuration of SOC technologies, including SIEM, EDR, IDS/IPS, firewalls, and vulnerability management tools.
- Engage with partners to secure cloud offerings based on industry best and standard practices.
Compliance & Governance :
- Support SOC 2 and ISO 27001 audit activities, ensuring adherence to compliance standards and facilitating external audits.
- Maintain working knowledge of regulatory requirements (GDPR, HIPAA, PCI-DSS) and apply them to operational security controls.
- Contribute to the development and maintenance of security standards, guidelines, policies, and documentation.
- Collaborate with the GRC (Governance, Risk, and Compliance) function to drive a cohesive security program.
Reporting & Stakeholder Communication :
- Prepare reports and presentations for senior management detailing the current security landscape, recent incidents, and their resolution.
- Manage and report on periodic KPIs and SLA adherence related to SOC operations and platform performance.
- Participate in project and scrum planning prioritization alongside the broader security team.
- Mentor junior analysts and contribute to improving team knowledge through knowledge sharing and hands-on training.
Who You Are :
Experience :
- 10-12 years of relevant technical experience in information security, with at least 5 years in a SOC or security operations role.
- Demonstrated hands-on experience with security tools : SIEM (Datadog, Splunk, Microsoft Sentinel), EDR, IDS/IPS, and vulnerability management platforms.
- Proven experience troubleshooting and responding to security events and incidents in cloud environments.
- Hands-on experience supporting security audits (SOC 2, ISO 27001) and working with external auditors.
Technical Skills :
- Strong hands-on AWS security depth (IAM, Security Hub, GuardDuty) and Azure security depth (Defender for Cloud, Sentinel/Defender).
- Strong Kubernetes and container security experience (cluster hardening, workload identity, runtime controls, image scanning).
- Proven Security Operations automation : triage and response automation, detection engineering, and playbook automation (SOAR/workflows/scripts).
- Strong hands-on Datadog (SIEM/security monitoring), dashboards, alert tuning, and investigation workflows; Splunk/Sentinel familiarity a plus.
- Practical AI/ML skills for SecOps (alert enrichment, correlation, anomaly detection, summarization) and responsible use of AI tools to improve analyst productivity.
- Strong Google Workspace security administration and identity protections (admin controls, audit logs, OAuth app governance).
- Vulnerability management expertise end-to-end (asset discovery, prioritization, remediation verification) and risk-based reporting.
- Strong understanding of networking concepts : VPN, DNS, Routing, Firewalls, and Load Balancing.
- Working knowledge of access control, directory services, and authentication protocols (OAuth, SAML, OpenID).
- Scripting skills in Bash, Python, Terraform, AWS CloudFormation, and API/REST integrations are a strong plus.
- Strong Palo Alto firewall knowledge (policy design, threat prevention, logging, troubleshooting) is a plus.
Education & Certifications :
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience).
- One or more professional certifications preferred : CISSP, CISM, CompTIA Security+, GCIA, GCIH, or equivalent offensive security certifications.
Soft Skills :
- Strong problem-solving skills, attention to detail, and a self-learning mindset.
- Excellent communication skills.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1646480