Requirements
- 3+ years of experience in a SOC or SecOps Engineering role, with a strong background in both alert triage and security engineering
- Proficiency in Python: Ability to write clean code to automate workflows or interact with security APIs
- Cloud Fluency: Experience with security monitoring and incident response in cloud environments (AWS/GCP/Azure)
- Infrastructure as Code: Familiarity with managing security configurations through Git-based workflows
- Framework Knowledge: Strong understanding of attack vectors and the MITRE ATT&CK framework
- Education: A degree in a cyber-related field or relevant certifications (e.g., CompTIA Security+, CySA+, GCIH) is beneficial
- We are looking for engineers who are masters of automation but remain grounded in analyst fundamentals. You should have a keen interest in leveraging AI and Large Language Models (LLMs) to reduce SOC toil – using AI to summarise complex alerts, auto-generate YARA-L detections, or build intelligent playbooks to stay ahead of modern threats
- You may be put off applying for a role because you don’t tick every box. Forget that! While we can’t accommodate every flexible working request, we’re always open to discussion. So, if you’re excited about working with us, but aren’t sure if you’re 100% there yet, get in touch anyway
What the job involves
- To support our rapid growth, we are looking for talented engineers to join our foundational in‑house SecOps team. This is a “Full‑Stack” security role: you will move beyond traditional monitoring to develop and operate our security capabilities
- Active Monitoring: Monitor security alerts and events generated by the SecOps platform and integrated cloud security tools
- Triage & Analysis: Perform deep‑dive analysis of security incidents and anomalies, accurately distinguishing between true positives and false positives
- Prioritisation: Manage the incident queue, prioritising alerts based on severity, potential impact, and business criticality
- Detection as Code: Design and maintain sophisticated detection logic using YARA‑L. Manage the lifecycle of these rules and configurations using IaC principles for version control
- SOAR Extension: Lead the automation of response playbooks. You will write and extend SOAR capabilities using Python, creating custom integrations and “Managers” to connect SecOps with internal APIs
- Tool Optimisation: Identify opportunities for automation to streamline operations and contribute to the continuous tuning and maintenance of SOC tools
- End‑to‑End Investigation: Investigate incidents thoroughly, leveraging logs from platforms, endpoints, and applications mapped to the Unified Data Model (UDM)
- Incident Lifecycle: Lead containment, eradication, and recovery efforts in collaboration with Security and Technology teams
- Documentation: Maintain comprehensive records of incident details, findings, and remediation steps to ensure a high standard of auditability
- Group Collaboration: Work closely with the Group SOC team to align on global security standards and coordinate response efforts during cross‑entity incidents
- Threat Hunting: Stay informed about the latest cyber threats and cloud‑specific vulnerabilities, conducting proactive threat‑hunting activities using available telemetry
#J-18808-Ljbffr…
