Security Operations Analyst - Detection Engineering & Threat Hunting, Global SOC
Core
Build high-fidelity detections, conduct threat hunts, and automate response workflows to monitor and protect enterprise IT infrastructure.
Role type
Senior IC detection engineer (threat hunting & SOC)
Builds
Detection logic, SOAR playbooks, and automated response workflows for enterprise IT security
Domain
Cybersecurity, Threat Intelligence, SOC Operations
Required skills
SIEM platforms, EDR tools, detection logic tuning, threat modeling, MITRE ATT&CK, scripting (Python/PowerShell), log analysis
Preferred skills
SOAR platforms, detection-as-code pipelines, GitOps, CI/CD rule deployment, threat hunt frameworks, purple team exercises, red teaming, malware analysis, digital forensics
Technologies
Splunk, Chronicle, Elastic, SentinelOne, CrowdStrike, Sigma, EQL, KQL, YARA
Responsibilities
Monitor security alerts and events from SIEM, IDS/IPS, firewalls, and EDR systems; Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry; Reduce alert fatigue through improved severity tagging and enrichment workflows; Conduct threat hunts based on TTPs and threat intelligence; Design and maintain SOAR playbooks for triage and response; Contribute scripts to improve investigation efficiency; Assist in post-incident reviews and coordinate lessons learnt.
Seniority
Senior, hands-on IC