At a Glance
- Tasks: Join us as a Security Engineer, focusing on automating security operations and enhancing incident response.
- Company: Be part of a dynamic team in the security and investigations industry, driving innovation.
- Benefits: Enjoy flexible work with 2 days in the office and 3 days remote, plus competitive pay.
- Why this job: Make a real impact by improving security processes and collaborating with experts in the field.
- Qualifications: 3+ years in cybersecurity, with skills in automation, SIEM, and cloud security tools required.
- Other info: This is a contract role for 6 months, ideal for tech-savvy individuals eager to innovate.
Start date: ASAP
Duration: 6 Months
Location: 2 days in Cambridge office, 3 days working from home
Rate: £700 - £790 per day inside ir35
Summary: Utilizing knowledge of security operations, incident response, and detection engineering, you will be responsible for the delivery of SIEM detections and security automations. The successful candidate will be proficient in automation and orchestration tools (e.g., SOAR platforms, scripting languages like Python, PowerShell) and have experience with integrating security tools (e.g., SIEM, EDR, firewalls) APIs, and Case Management tools for data enrichment.
Responsibilities:
- Build security automations, logging, and SIEM detections to improve the CDO's efficiency, scalability, and incident response capabilities.
- Design, implement, and maintain automated workflows and playbooks to streamline CDO operations, including incident response, threat hunting, cyber threat intelligence and vulnerability management.
- Collaborate with CDO analysts to identify repetitive tasks and automate them to improve operational efficiency.
- Collaborate with Threat Intelligence, Incident Response, and Attack Surface Management to build and tune robust SIEM detections for both proactive and reactive response actions.
- Continuously evaluate automation solutions for performance, reliability, and scalability, making improvements, as necessary.
- Collaborate with third-party vendors and service providers to leverage automation opportunities and ensure successful integrations.
- Lead technical migration of log sources into Microsoft Sentinel SIEM.
Key Skills:
- Demonstrated ability in cybersecurity, with at least 3 years in a technical role in security operations and/or security software development.
- Solid understanding of security operations, automations standard processes, detection engineering and SIEM management.
- Experience with cloud security tools and platforms (e.g. Azure, AWS, Google Cloud) and their integration into SOC operations.
- Vendor-specific certifications for SOAR platforms (e.g., Sentinel SOAR, Splunk SOAR, Palo Alto Cortex XSOAR).
- Experience contributing to large-scale, sprint-based, security automation and detection engineering projects.
Nice to have skills:
- Ability to develop and implement long-term automation strategies aligned with security operation objectives.
- Ability to translate technical concepts into clear, actionable insights for technical and non-technical partners.
- Meticulous focus on ensuring accuracy, reliability, and security in automation workflows.
- Consistent record of implementing automation and integration solutions in a SOC or similar environment.
Seniority level: Not Applicable
Employment type: Contract
Job function: Information Technology
Industries: Security and Investigations
Security Engineer employer: Trust In SODA
Contact Detail:
Trust In SODA Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Engineer
✨Tip Number 1
Familiarise yourself with the specific automation and orchestration tools mentioned in the job description, such as SOAR platforms and scripting languages like Python and PowerShell. Having hands-on experience or projects that showcase your skills in these areas can set you apart from other candidates.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who work in security operations or have experience with SIEM and EDR tools. Engaging in discussions on platforms like LinkedIn or attending relevant meetups can help you gain insights and potentially get referrals.
✨Tip Number 3
Stay updated on the latest trends and challenges in cybersecurity, particularly around incident response and threat hunting. Being able to discuss current events or recent breaches during an interview can demonstrate your passion and knowledge in the field.
✨Tip Number 4
Prepare to discuss specific examples of how you've implemented automation solutions in previous roles. Highlighting your ability to improve operational efficiency through automation will resonate well with the hiring team and show that you can contribute immediately.
We think you need these skills to ace Security Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in security operations, incident response, and automation. Use specific examples that demonstrate your proficiency with tools like Python, PowerShell, and SIEM systems.
Craft a Strong Cover Letter: In your cover letter, express your enthusiasm for the role and how your skills align with the responsibilities outlined in the job description. Mention your experience with cloud security tools and your ability to collaborate with teams.
Showcase Relevant Projects: If you have worked on significant projects related to security automation or detection engineering, include them in your application. Detail your contributions and the impact they had on operational efficiency.
Highlight Certifications: List any relevant certifications, especially those related to SOAR platforms or cloud security. This will help demonstrate your commitment to professional development and expertise in the field.
How to prepare for a job interview at Trust In SODA
✨Showcase Your Technical Skills
Be prepared to discuss your experience with automation and orchestration tools, especially Python and PowerShell. Highlight specific projects where you've successfully integrated security tools and built SIEM detections.
✨Demonstrate Problem-Solving Abilities
Expect questions that assess your ability to identify and automate repetitive tasks. Share examples of how you've improved operational efficiency in previous roles through automation solutions.
✨Familiarise Yourself with the Company’s Tools
Research the specific security tools and platforms the company uses, such as Microsoft Sentinel SIEM. Understanding their environment will help you tailor your responses and show your readiness to contribute.
✨Prepare for Scenario-Based Questions
Be ready to tackle scenario-based questions related to incident response and threat hunting. Think about how you would approach real-world security challenges and articulate your thought process clearly.