An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Nityo Infotech Services Philippines Inc. is seeking a security engineer to develop and refine SIEM/XDR use cases, integrating Splunk ES, Microsoft Sentinel, and Defender to enhance detection accuracy.
You will script and automate via Python, PowerShell, or Bash, work with BAS testing, and produce security monitoring dashboards and reports. The role is hybrid in Alabang with EU Timezone flexibility.
Develop and implement new security use cases for SIEM/XDR platforms.
Fine-tune existing use cases to reduce false positives and improve detection accuracy.
Develop and maintain scripts, APIs, and integrations to enrich SIEM/XDR capabilities.
Support the implementation and maintenance of Breach & Attack Simulation (BAS) threats for automated detection testing.
Maintain and enhance existing security integrations and automation.
Evolve security detection technologies based on the defined technology roadmap.
Collaborate with Security Detection and Incident Response teams to improve detection and response capabilities.
Manage and deliver security monitoring reports and dashboards.
Ensure proper documentation in accordance with established SOPs, working instructions, and governance requirements.
Prepare and present security monitoring status, trends, and updates to technology SMEs and management.
Collaborate with risk and information security teams on security monitoring and detection initiatives.
Proven experience developing SIEM/XDR security use cases.
Hands-on experience with platforms such as:
Splunk Enterprise Security
Microsoft Sentinel
Microsoft Defender
SIEM/XDR certifications are an advantage.
Strong scripting/programming experience using Python, PowerShell, and/or Bash.
Experience with API integration and security automation.
Experience with Breach & Attack Simulation (BAS) and threat creation is preferred.
Experience with ServiceNow or similar reporting/ticketing platforms.
Knowledge of common security vulnerabilities, remediation, prioritization, change management, analysis, and incident triage.
Strong understanding of security monitoring and detection engineering.
Excellent written and verbal English communication skills.
Experience working in virtual, international, and multicultural environments.
Strong analytical, problem-solving, communication, teamwork, agility, and results-oriented skills.
Security certifications are an advantage but not mandatory, such as:
Security+ CE | GCIH | ECIH | OSCP | CEH
Working Arrangement: Hybrid set-up in Alabang, EU Timezone but the candidate should be flexible if needed.