- Experience in designing, developing and maintaining detection rules, alerts and analytics across SIEM, EDR/XDR and cloud security tools (e.g., Splunk, Microsoft Sentinel, Azure, AWS) ;
- Experience supporting or mentoring less-experienced analysts, providing constructive feedback on investigation quality and reporting standards ;
- Practical experience with automation or SOAR use cases, identifying repetitive manual tasks and creating enrichment or workflow improvements.
- Experience working in a regulated , high control environment such as defence , government , financial services or other enterprise sectors ;
- Hands on experience with cloud native security monitoring ( Azure , AWS) and hybrid environments ;
- Experience with developing detections from network and Edge security devices such as Cisco, Fortinet / Fortigate , Palo Alto , or comparable appliances .
Duties/role:
Reviewing and validating investigations, supporting First-Line Analysts to ensure that alert closures, escalations, supporting evidence, and investigation notes meet CSOC quality standards, while confirming completeness, accuracy, and procedural compliance ;
Acting as the technical escalation point for cyber security monitoring ;
Performing in-depth log analysis and threat triage using SIEM and SOAR platforms, including Splunk Enterprise Security, Splunk SOAR, Microsoft Sentinel, and supporting security tools and data sources.