We are seeking an experienced Level 3 Security Engineer with strong expertise in Security Operations, Detection Engineering, SIEM/SOAR, EDR, and cloud security. The ideal candidate will support advanced security monitoring, detection development, alert tuning, and incident investigation across enterprise environments.
Primary Responsibilities
- Monitor and investigate advanced security events using SIEM, SOAR, EDR, email security gateways, and firewalls.
- Develop, implement, and maintain security detections, rules, and alerts.
- Perform rule and alert tuning to improve detection accuracy and reduce false positives.
- Conduct advanced security investigations and support incident response and threat analysis.
- Map security detections and activities to the MITRE ATT&CK framework, including relevant tactics and techniques.
- Develop and enhance detection use cases based on emerging threats and attack patterns.
- Work across AWS, Azure, and/or GCP environments to monitor and improve cloud security.
- Collaborate with Security Operations, Incident Response, Threat Intelligence, and Engineering teams.
- Troubleshoot complex security monitoring and detection issues and provide Level 3 technical support.
- Continuously improve security monitoring, detection coverage, and operational processes.
Required Skills
- Strong experience in Security Operations / Security Engineering.
- Hands-on experience with SIEM/SOAR, EDR, email security, and firewall technologies.
- Proven experience in Detection Engineering.
- Experience developing and tuning security rules, alerts, and detection logic.
- Strong understanding of the MITRE ATT&CK framework.
- Experience with AWS, Azure, and/or GCP security environments.
- Familiarity with Google Security Operations.
- Strong analytical, troubleshooting, and incident investigation skills.