Basic requirement
You will be involved in full cycles of designing, building, fine tuning and improving security detection and response capabilities; use data analytics, define and implement new tooling and collaborate with stakeholders to improve response actions in a large cyber defense SOC environment with a focus on SIEM content.
About the client
Our client, a service-based organization offering IT solutions and Managed Services, accelerates digital transformation and builds a more resilient, sustainable and inclusive future for SMEs.
Requirements
Required Technologies
- KQL
- Machine Learning
- REST API
- Automation
- Python
Skills and competencies
- Transform data into informative Security alerts.
- Analyse threat actors techniques and develop resilient detection content.
- Participate in purple teaming exercises and improve existing detection.
- Develop machine learning models to detect behavioural aspects to drive Security Detection.
- Develop playbooks to automate response actions.
- Experience in creating threat detection use cases/models.
- A strong defensive mindset with a good understanding of threat actors TTPs and how to defend against these.
- Experience in working with Microsoft security products.
- Experience with programming (preferably Python, REST API), automation or machine learning.
- Strong skills in query languages like SPL, and KQL.
- Strong (interpersonal) communication skills in the English language, both written and verbal.
- Security certifications such as OSCP, GPEN, GCFA, GMON, and GCDA are preferred.
Benefits
- Travel allowance
- An open culture where you can express your views
- Excellent Work life balance
- Visa sponsorship
- A great group of like-minded colleagues
- Relocation support
Required Technologies KQL Machine Learning REST API Automation Python Skills and competencies Transform data into informative Security alerts. Analyse threat actors' techniques and develop resilient detection content. Participate in purple teaming exercises and improve existing detection. Develop machine learning models to detect behavioural aspects to drive Security Detection. Develop playbooks to automate response actions. Experience in creating threat detection use cases/models. A strong defensive mindset with a good understanding of threat actor's TTPs and how to defend against these. Experience in working with Microsoft security products. Experience with programming (preferably Python, REST API), automation or machine learning. Strong skills in query languages like SPL, and KQL. Strong (interpersonal) communication skills in the English language, both written and verbal. Security certifications such as OSCP, GPEN, GCFA, GMON, and GCDA are preferred.