Hello,
I have below exclusive position with one of our Client. Please review the requirement criteria below and revert to me with your updated resume so that we can move ahead for further steps.
Job Title: Detection Engineer/ SOC Integration
Location: 100% Remote
Duration: 12+ Months Contract Potential for extension
Responsibilities:
• Ingest and normalize every source so an analyst can pivot on user, session, and model - without this the SIEM holds data nobody can investigate with
• Write the detections: usage and cost anomalies, connector and tool-use activity, failed DLP and guardrail events, grant scope widened, managed-settings tamper, ZDR setting changed
• Tune to a false-positive rate the SOC will actually work - an alert set that floods the queue gets muted in week three and the control is then decorative
• Build and validate the four WS7 IR runbooks against containment capabilities that actually exist.
Must Have:
• Production detection engineering in Google SecOps and/or Cribl - has written, tuned, and maintained real content
• Has built SaaS audit log ingestion from API sources: pagination, cursor management, rate limiting, backfill
• Has written IR runbooks that were used in a real incident and revised afterward
Mission:
- Turn the telemetry every other workstream produces into working detections, alerts, and runbooks inside Client existing SOC.