The SOC Detection & Platform Engineer is responsible for developing high-quality security detections and ensuring the stability, scalability, and efficiency of the organization’s SIEM/SOAR platforms. This role combines advanced detection engineering with hands‑on platform operations to support a mature and proactive Security Operations Center (SOC).
Key Responsibilities – Detection Engineering
- Develop, enhance, and maintain security detection use cases aligned with the MITRE ATT&CK framework.
- Design and implement correlation rules, behavioral analytics, and alert logic across various log sources.
- Perform false positive reduction, threshold optimization, and tuning of detection logic.
- Validate detection coverage through attack simulation and adversary emulation activities.
- Maintain documentation including rule logic, mapping, and use‑case repositories.
- Collaborate with Threat Intelligence and SOC teams to enhance detection effectiveness.
- Manage and optimize SIEM/SOAR platforms for availability and performance.
- Handle log onboarding, parsing, normalization, enrichment, and schema alignment.
- Maintain stable data pipelines including ingestion, indexing, and retention.
- Integrate new log sources across endpoint, network, cloud, and application environments.
- Develop and maintain SOAR playbooks and automation workflows.
- Conduct platform health checks and configuration audits.
- Work with cross‑functional teams to improve SOC visibility and detection maturity.
- Support platform upgrades and capability enhancements.
- Participate in threat‑hunting and purple‑team exercises.
- Ensure compliance with documentation and change management processes.
Required Skills & Experience
- 4–8 years of SOC, detection engineering, or SIEM/SOAR experience.
- Hands‑on expertise with SIEM tools such as Sentinel, Splunk, Elastic, or QRadar.
- Proficiency with query languages (KQL, SPL, SQL, etc.).
- Strong understanding of cybersecurity principles and threat actor behaviors.
- Experience with automation scripting (Python, PowerShell, Bash).
- Familiarity with log pipelines and normalization concepts.
Preferred Qualifications
- Experience with Detection‑as‑Code (Sigma).
- Exposure to cloud security (Azure, AWS, GCP).
- Experience with attack simulation tools (Atomic Red Team, Caldera).
- Understanding of SIEM data engineering processes.
- Strong analytical and problem‑solving skills.
- Ability to work in fast‑paced environments.
- High attention to detail and focus on operational excellence.