GENERAL RESPONSIBILITIES:
The role is responsible for the engineering, integration, optimisation, and maintenance of SOC platforms, particularly SIEM, SOAR, and log management technologies. The role focuses on building and improving the security platform rather than performing day-to-day SOC analyst activities.
DUTIES AND RESPONSIBILITIES:
- SOC Platform Engineering
- Configure, maintain, and fine-tune SIEM, SOAR, and other SOC platforms.
- Optimise platform performance, reliability, and detection capabilities.
- Troubleshoot platform and integration issues.
- Log Source Integration
- Onboard and integrate security and technology log sources into the SOC platform.
- Configure ingestion, parsing, normalisation, and enrichment.
- Validate data quality and troubleshoot ingestion issues.
- Detection Engineering
- Develop, configure, and fine-tune detection rules and correlation use cases.
- Translate customer security requirements into actionable detections.
- Take onboarded log sources through to customer-specific detection capabilities.
- SOAR and Automation
- Configure and optimise SOAR playbooks, workflows, and integrations.
- Support security automation and automated enrichment/response capabilities.
- Platform Maintenance and Uplift
- Perform platform patching, upgrades, configuration changes, and maintenance.
- Support continuous improvement and uplift of SOC platform capabilities.
- Operations and Troubleshooting
- Provide technical support for platform, ingestion, integration, and detection issues.
- Conduct root-cause analysis and implement corrective actions.
- Monitor platform health and performance.
- Customer and Stakeholder Support
- Work with customers and SOC teams to understand monitoring and detection requirements.
- Provide technical guidance on log onboarding, integrations, detections, and automation.
- Maintain technical documentation and support knowledge transfer.
LEADERSHIP COMPETENCIES:
N/A
FUNCTIONAL/TECHNICAL COMPETENCIES:
Information Security, Release and Deployment, Configuration Management, Incident Management, Systems Installation and Removal, Methods and Tools,
CORE COMPETENCIES:
Teamwork & Collaboration, Accountability, Customer Focus, Communication, Innovation, Quality
JOB SPECIFICATIONS:
- Education- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, Engineering, or related discipline. Relevant cybersecurity or vendor certifications are an advantage.
- Related Work Experience - Minimum 5 years of relevant experience in SecOps/SOC platform engineering.
- Hands-on experience with SIEM and/or SOAR platforms.
- Experience onboarding and integrating multiple log sources.
- Experience developing and fine-tuning security detections and monitoring use cases.
- Experience with SOC platform maintenance, patching, upgrades, and troubleshooting.
- Experience in an enterprise SOC, MSSP, managed security services, or cybersecurity operations environment.
- Knowledge
- Security Operations (SOC) platforms, technologies, and operating concepts
- SIEM, SOAR, and security log management technologies
- Security event collection, log source onboarding, ingestion, and data pipelines
- Log parsing, normalization, enrichment, and data quality concepts
- Detection engineering, correlation rules, and security monitoring use cases
- Security automation, orchestration, and SOAR playbook concepts
- Security platform integrations, including APIs, Syslog, and related integration methods
- SOC platform administration, configuration, performance monitoring, and troubleshooting
- Platform lifecycle management, including patching, upgrades, and configuration changes
Skills
- Strong analytical, problem-solving, and technical troubleshooting skills
- Ability to engineer, configure, integrate, and optimize security platforms
- Ability to develop, tune, and improve security detections and related use cases
- Ability to translate customer and operational requirements into practical technical solutions
- Strong technical documentation and communication skills
- Ability to collaborate effectively with SOC analysts, security engineers, technical teams, and customers
- Strong technical ownership, accountability, and attention to quality
- Continuous improvement mindset with the ability to identify and implement platform enhancements
- Effective stakeholder management and customer orientation
- Ability to share technical knowledge and provide guidance to relevant teams