Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
WE Soda in Türkiye seeks a hands-on Senior Security Specialist to drive incidents from detection to resolution. You will coordinate with MSSP/SOC, Group IT, Türkiye IT, and external providers to validate alerts and document outcomes.
The role requires strong expertise in LogRhythm SIEM, EDR tools, and Windows security fundamentals, with experience across international teams and email security tooling.
We are seeking a hands‑on Senior Security Specialist to act as the primary internal liaison with our MSSP/SOC, driving cybersecurity incidents from detection through to resolution.
This role will work closely with Group IT, Türkiye IT, US IT, and external security providers to validate alerts, challenge incomplete investigations, coordinate containment and remediation actions, and ensure incidents are properly documented and closed.
They must be able to make sound operational decisions during live security events, communicate clearly with technical and non-technical stakeholders, and convert MSSP/SOC escalations into real internal action.
At least one relevant cybersecurity certification is required, such as:
Additional certifications such as GCIA, GCED, GMON, CEH, ITIL Foundation, ISO 27001 Lead Implementer / Lead Auditor, or vendor training in LogRhythm, SentinelOne, Proofpoint, Microsoft Sentinel, or Defender would be advantageous.
Practical incident response, MSSP/SOC coordination, and LogRhythm experience will be weighted more heavily than certification alone.
We are looking for someone calm and structured under pressure, with strong analytical skills, clear ownership, and a hands‑on approach to problem solving.
They must be confident challenging both suppliers and internal teams when required, while remaining professional and constructive. They must be comfortable working across countries and time zones, particularly with Group IT, Türkiye IT, US IT, and the MSSP/SOC provider.
Excellent professional English, both written and spoken, is mandatory. They must be able to lead technical incident calls, write clear incident summaries, prepare management updates, and communicate effectively with senior stakeholders.