About
the Role
We are operating and continuously
improving an internal Security Operations Center (SOC) platform built
as an end-to-end security monitoring system. The platform covers log
collection, data normalization, threat detection, and alert handling. The
core platform is already built and running stably in production.
This role is not about
building a SOC platform from scratch. Instead, you will focus on expanding
data coverage, especially new log sources generated as the company moves its
infrastructure to private cloud, standardizing logs using UDM,
improving threat detection capabilities, and maintaining and enhancing existing
SOC components.
What
You Will Do?
·
Research, design, and integrate new log
sources
Integrate network, cloud/private cloud, audit, and other log sources into the
existing data pipeline.
·
Develop and improve detection rules
Create and extend anomaly and threat detection rules using Sigma,
Drools (DRL), and Wazuh rules/decoders, with a focus on improving coverage
of the MITRE ATT&CK framework.
·
Document the SOC platform
Document system architecture, detection logic, log schemas, and operational
processes to ensure the platform can be maintained and operated effectively in
the long term.
·
Build and improve correlation detection
Work with other teams to develop base and correlation detection rules, and
evaluate their effectiveness using real-world security cases.
·
Maintain and improve existing SOC components
Proactively maintain, troubleshoot, and improve existing components,
including Falco, Wazuh, Flink pipelines, Drools, TheHive, and AI-based
alert triage. Independently investigate and resolve production issues
related to the SOC infrastructure.
·
Evaluate and propose new solutions
Research, evaluate, and recommend new or alternative technologies within the
SOC ecosystem when needed for future expansion or improvement. This may include
evaluating alternatives to Falco.
·
Support Incident Response
Work with relevant teams to investigate and respond to security incidents when
attacks or suspicious activities are detected.
Requirements:
Must-Have
·
4–5+ years of experience in Security
Operations, Security Analysis, or a related security role.
·
Hands-on experience operating a SOC
environment, including: MITRE ATT&CK, YARA rules, Drools
rules, UDM, Apache Flink, Wazuh, ELK, SIEM
·
Practical experience with log
normalization using UDM (Google SecOps/Chronicle Unified Data Model) or
a similar standardized log/data model.
·
Good programming and coding skills, with the
ability to read, write, integrate, and customize components in a SOC
environment, especially UDM, Drools, Flink, and data pipelines.
·
Strong debugging and troubleshooting skills,
with the ability to independently investigate and resolve production issues
involving components such as Falco, Wazuh, Flink, Drools, and TheHive.
Nice-to-Have
·
Experience with Public/Private Cloud,
Kubernetes, CI/CD, Linux, Kafka, Vector, ELK, ClickHouse, and S3.
·
Experience with other open-source tools and
technologies in the SOC ecosystem, such as Tetragon, AppArmor, Kyverno,
Threat Intelligence, and Threat Hunting.
·
Experience training or building custom
ML models to improve alert classification, beyond prompt-based
approaches.
·
Ability to provide technical recommendations and
propose improvements to SOC architecture and operational processes.
·
Experience designing and fine-tuning LLM
prompts for security alert classification and automation, such as
identifying True Positive / False Positive alerts.
Why
You'll Love Working Here
Inside our lean engineering team:
·
We work on large and complex systems, with a
focus on ownership and continuous learning.
·
We work within existing constraints and improve
systems incrementally.
·
We value strong fundamentals and the ability to
reason through unfamiliar or complex systems.
·
Collaboration is direct, and discussions focus
on solving problems and delivering results.
Our offers include:
·
MacBook provided
·
Full salary insurance
·
Health care insurance
·
19 leave days
·
Annual health check-up