Source description
About the role
Threat Detection & Incident Response • Lead end-to-end investigation of complex security incidents (malware, phishing, lateral movement, cloud compromise) • Perform advanced threat hunting using SIEM, EDR, and cloud telemetry • Conduct deep forensic analysis (endpoint, network, logs, email headers) • Act as L3 escalation point for high-severity incidents Detection Engineering & SOC Optimization • Design and implement high-fidelity detection rules and use cases • Tune SIEM correlation rules to reduce false positives and improve signal quality • Develop and enhance SOC playbooks aligned with MITRE ATT&CK • Build dashboards, reports, and detection logic for continuous improvement Security Tooling & Platforms • Lead implementation and optimization of: o SIEM: Microsoft Sentinel / Splunk / QRadar o EDR/XDR: Defender, CrowdStrike, SentinelOne o Email Security: Proofpoint, Mimecast, Defender for Office o WAF & Network Security tools • Manage integrations across multi-vendor security stack Automation & SOAR • Develop automation playbooks (SOAR) for triage, enrichment, and response • Reduce MTTD/MTTR through automation and workflow optimization Cloud Security & DevSecOps • Monitor and secure cloud environments (AWS/Azure) • Implement logging and detection using: CloudTrail, VPC Flow Logs, Defender, Sentinel • Collaborate with engineering teams to embed security into CI/CD pipelines • Drive DevSecOps practices (SAST, DAST, IaC scanning, policy-as-code) Risk, Compliance & Governance • Perform vulnerability assessments and risk analysis • Ensure alignment with frameworks: NIST, CIS Benchmarks, GDPR, PCI-DSS • Support audits and compliance initiatives Leadership & Collaboration • Mentor junior analysts and uplift SOC capabilities • Work cross-functionally with Dev, Cloud, and Infra teams • Provide insights and reporting to leadership
Advanced incident response & L3 security investigation Threat hunting using SIEM, EDR/XDR, and cloud telemetry Digital forensics (endpoint, network, email, and log analysis) Detection engineering & SIEM rule tuning (MITRE ATT&CK aligned) SOC optimization, playbook development, and reporting Security tooling expertise (Sentinel, Splunk, QRadar, Defender, CrowdStrike) SOAR automation for triage, response, and MTTR reduction Cloud security & DevSecOps (AWS/Azure, CI/CD security, IaC scanning) Risk management, compliance (NIST, CIS, GDPR, PCI‑DSS) & team leadership
More at Bahwan CyberTek