Role & Responsibilities: Security Monitoring & Incident Response: Execute/lead initial containment, forensics scoping, and stakeholder updates; align with both best industry practice and internal IR playbooks. Lead investigations across Defender XDR/MDE and CrowdStrike (process trees, lateral movement, identity signals). Use Tanium for rapid endpoint scoping and live response actions (as per policy). Analyse Joe Sandbox reports (behaviour trees, network indicators, dropped files); derive IOCs/YARA candidates; coordinate containment. Design/maintain Cortex XSOAR playbooks (data enrichment, containment workflows, approvals, notifications); implement guardrails. Threat Detection & Hunting: Deep familiarity with Azure AD/Entra ID, Azure Activity/Signin logs, M365 audit logs, as well as AWS and GCP logs. Author and tune analytic rules in Sentinel (KQL), Elastic (DSL/EQL/KQL/ESQL), Sigma; reduce false positives; add entity mapping and suppression logic. Proactive hunts using ATT&CK-aligned hypotheses (credential theft, persistence, C2); pivot across endpoint, identity, network, and cloud logs. Maintain GitLab repos (branching, merge requests, CI checks for detections) and workflows for detection content (code reviews, approvals, CI quality checks). Expertise: Deep knowledge of SIEM, SOAR, and EDR platforms. Deep knowledge of threat intelligence, and incident response frameworks. Familiarity with MITRE ATT&CK, NIST, and ISO 27001 standards. Ability to analyse logs, network traffic, and malware indicators.
Required Qualifications
Defender XDR/MDE expertise
CrowdStrike investigation
Tanium endpoint management
Joe Sandbox analysis
Cortex XSOAR playbook design
Azure AD/Entra ID monitoring
AWS & GCP log analysis
Microsoft Sentinel (KQL)
Elastic Stack (DSL/EQL/KQL/ESQL)
Sigma rule authoring
GitLab version control
SIEM & SOAR platform proficiency
Threat Intelligence frameworks
Incident Response methodologies
MITRE ATT&CK mapping
NIST & ISO 27001 compliance
Preferred Qualifications
YARA rule development
Advanced false positive reduction
Entity mapping & suppression logic
CI/CD pipeline integration for security detections