|
|
Strong knowledge of SOC processes: monitoring, triage, incident response, escalation
Hands‐on experience with SIEM tools (Splunk, QRadar, Sentinel, ArcSight, etc.)
Hands‐on experience with SOAR platforms (Cortex XSOAR, Splunk SOAR, IBM SOAR, etc.)
Incident Response & Threat Analysis (MITRE Telecommunication&CK, kill chain, IOC analysis)
Experience with security tool integration (EDR, IDS/IPS, Email Security, Firewall)
Strong scripting/automation skills (Python, PowerShell, or Bash)
Experience in playbook development and automation workflows
Good understanding of network, endpoint, and cloud securityExperience in use‐case development, alert tuning, and false‐positive reduction
Knowledge of cloud security platforms (Azure, AWS, GCP)
Exposure to EDR/XDR tools (CrowdStrike, Defender, SentinelOne, Palo Alto Cortex)
Experience with vulnerability management tools (Qualys, Tenable, Rapid7)
Security certifications: GCIA, GCIH, GCED, CEH, CISSP, Azure Security (preferred)
Experience in client-facing roles and handling audits or compliance requirements
Familiarity with DevSecOps and API-based integrations
|
|
|
Experience in use‐case development, alert tuning, and false‐positive reduction
Knowledge of cloud security platforms (Azure, AWS, GCP)
Exposure to EDR/XDR tools (CrowdStrike, Defender, SentinelOne, Palo Alto Cortex)
Experience with vulnerability management tools (Qualys, Tenable, Rapid7)
Security certifications: GCIA, GCIH, GCED, CEH, CISSP, Azure Security (preferred)
Experience in client-facing roles and handling audits or compliance requirements
Familiarity with DevSecOps and API-based integrations
|