SOC Engineer

  • -

LA International Computer Consultants Ltd

SOC Engineer
DV Clearance Required (Will consider SC candidates)
On site in Birmingham 5 days p/w
Inside IR35
Pay £575 – £600 p/d

* Core hours 09:00 – 17:00
* On-site in central Birmingham office
* On-call rota- paid
* Reviewing changes and approving or rejecting on behalf of SOC
* Raising SOC changes and gaining approval
* Updating IPS signatures
* Configuring SOC Desktops
* Linux administration & troubleshooting
* SIEM administration & troubleshooting
* Knowledge of log sources from different systems
* Experience writing queries using SPL, Kusto, SQL
* Writing playbooks, documentation, and troubleshooting guides
* Visio & network diagrams

Please apply for further details.

Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take up to a minimum 18 weeks. LA International is a HMG approved ICT Recruitment and Project Solutions Consultancy, operating globally from the largest single site in the UK as an IT Consultancy or as an Employment Business & Agency depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, LA International welcome applications from all sections of the community and from people with diverse experience and backgrounds.

Award Winning LA International, winner of the Recruiter Awards for Excellence, Best IT Recruitment Company, Best Public Sector Recruitment Company and overall Gold Award winner, has now secured the most prestigious business award that any business can receive, The Queens Award for Enterprise: International Trade, for the second consecutive period.

Pour postuler, envoyez votre CV et votre lettre de motivation par e-mail à candidature@elzei.fr

SOC Engineer

STHREE SAS pour HUXLEY

1) Context: Security Operations Center (SOC) delivers the following capabilities to the client entities around the globe: Security Monitoring and Detection, Security Incident Response and Threat Intelligence. There are 2 transversal services of the SOC allows increasing coverage and overall detection capability which are Log Onboarding Factory and Use Case Factory. This mission is a part of Use Case Factory. We are looking for the service of an external SOC Detection Expert with an expertise of detection engineering , responsible for designing, developing, and implementing detection use cases to increase client threat detection capability and meet stakeholder requirements. The mission also requires being conversant with performing complex data manipulations and analysis.

2) Scope of Service – The Service will do the following * Detection Use Case Development: Design and implement detection use cases and playbooks tailored to identify both known and emerging threats within the organization’s environment. Create custom update polices leveraging KQL and regex * Rule Creation & Optimization: Develop and fine-tune rules, signatures, and logic in SIEM, EDR, and NDR platforms to detect suspicious activities effectively while minimizing false positives. Maintain and define the detection engineering DevOps processes and toolset. * Threat Monitoring: Collaborate with SOC analysts to ensure that detection mechanisms are performing as intended and adjust them based on feedback and real-world events. * Automation & Integration: Work with the automation team to integrate detection capabilities into SOAR platforms, streamlining response processes and enhancing efficiency. Develop automated attack scenarios to continuously test use cases under development. Develop automation strategies to improve detection and investigation capabilities. * Collaboration with Threat Intelligence Teams: Utilize threat intelligence feeds and indicators to enhance detection mechanisms, ensuring that detection logic is informed by the latest threat actor TTPs (Tactics, Techniques, and Procedures). * Collaboration with Incident Response & Threat Hunting Teams: Partner with incident response and threat hunting teams to validate detection efficacy and refine strategies based on incident learnings. * Documentation & Expertise Sharing: Document detection strategies, rules, and processes, and share expertise with SOC teams to improve overall operational readiness. * Continuous Improvement: Stay updated on the latest developments in cybersecurity and detection technologies, continuously improving and refining detection methodologies. * Metrics & Reporting: Assist in tracking and reporting on the effectiveness of detection strategies, providing insights to improve SOC operations.

3) Expertise * 2 years Expertise in Information Security * 2 years expertise in a similar mission Technical Expertise * Expertise in detection engineering approach in depth * Expertise of regular expressions and their application in data manipulation and analysis * Expertise with Azure Sentinel SIEM platform * Preferred SIEM vendor certification of administrator level * Expertise using KQL at a senior developer level * Expertise of applying the MITRE ATT&CK Framework to security Use Cases * Expertise with different security attack vectors and means of protection * Expertise working with security platforms such as SIEM, SOAR, etc * Any relevant security certifications are a plus * English environment- mandatory

Depuis 20 ans Huxley est positionné parmi les acteurs principaux du recrutement dans le monde. Spécialisé dans l’IT, la finance et l’assurance nous sommes implantés mondialement dans 15 pays.
Nous aidons nos clients à optimiser leur recrutement en adoptant une approche personnalisée et une expertise métiers, délivrant ainsi un service sur mesure. Nous nouons quotidiennement des relations avec les talents et les entreprises les plus dynamiques du marché

Pour postuler, envoyez votre CV et votre lettre de motivation par e-mail à candidature@elzei.fr