Project Overview:
The role focuses on strengthening and enhancing the client's Security Operations Center (SOC) capabilities, with a particular focus on SIEM onboarding, threat detection, and security monitoring.
Key Responsibilities:
- Support application and infrastructure teams in onboarding systems and applications into the SIEM/SOC environment
- Analyze and integrate security-relevant log sources
- Design and optimize correlation rules and security use cases
- Conduct threat modeling and simulation exercises
- Monitor, investigate, and support the response to security incidents
- Collaborate with technical and business stakeholders
- Ensure compliance with SOC processes, security policies, and escalation procedures
- Create documentation and provide security recommendations
Required Skills:
- Proven experience in SIEM/SOC operations
- Strong knowledge of security monitoring and incident response
- Hands-on experience with SIEM platforms such as:
- Microsoft Sentinel
- Splunk
- QRadar
- Elastic Security
- Experience with log onboarding, correlation rule design, and threat detection
- Understanding of MITRE ATT&CK and threat modeling methodologies
- Strong knowledge of IT infrastructure, networking, and cybersecurity best practices
- Excellent analytical and communication skills
Nice to Have:
- Experience with EDR/XDR solutions
- Cloud security experience (Azure, AWS, GCP)
- Security certifications such as CISSP, CISA, OSCP, or CASP+
.png)

