
SOC Developer
Ensign InfoSecurity4 months ago
Kuala Lumpur, MalaysiaMid Level
Responsibilities
- Develop, customize, and maintain SIEM monitoring content including rules, alerts, correlation searches, and dashboards.
- Build SOAR automation playbooks for incident response.
- Integrate data sources into SIEM platforms and manage parsing, normalization, and enrichment.
- Create and maintain scripts and tools for threat detection, investigation, and reporting.
- Collaborate with SOC Analysts and Threat Hunters to develop and improve detection use cases.
- Develop detection logic based on threat intelligence and attack techniques such as MITRE ATT&CK.
- Collaborate with infrastructure and application teams to improve logging and telemetry.
- Maintain documentation for code, detection logic, use-case coverage, and automation workflows.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
- Strong experience with SIEM technologies such as Splunk, QRadar, or ELK.
- Experience with SOAR platforms such as Cortex XSOAR, Splunk Phantom, or IBM Resilient.
- Proficiency in Python, JavaScript, or Bash.
- Familiarity with REST APIs, JSON, and integration methods.
- Understanding of cybersecurity concepts, attack techniques, and defensive strategies.
- Familiarity with MITRE ATT&CK, cyber threat intelligence, and incident-handling workflows.
- GIAC GMON, GCDA, GCIA, or equivalent certification is advantageous.