SOFTSWISS Logo

SOFTSWISS

SOC Detection Engineer – Senior

Posted 5 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in T'bilisi
Senior level
Remote
Hiring Remotely in T'bilisi
Senior level
Owns the full lifecycle of security detections across Windows, Linux, and Kubernetes environments. Develops and maintains Splunk detection rules, queries, dashboards, and risk-based detections; improves telemetry quality and detection coverage; analyzes false positives and gaps; maps detections to MITRE ATT&CK; and supports incident response, threat hunting, purple teaming, and attack emulation. Collaborates across SOC, infrastructure, engineering, and threat intelligence teams while contributing to automated testing and CI/CD workflows.
The summary above was generated by AI
Overview:

SOFTSWISS is hiring a Senior SOC Detection Engineer to join our Security Operations team. We are seeking a hands-on security professional to help build and develop our detection engineering function, strengthening the company’s ability to identify, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments.

Purpose of the role:

You will be responsible for owning the full lifecycle of security detections, from researching attack techniques and defining logging requirements to developing, testing, deploying, and continuously improving detection content in Splunk. Your work will help enhance detection coverage, improve telemetry quality, reduce false positives, and ensure that security teams can reliably identify and respond to real threats.

Key responsibilities:
  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.

  • Translate incident investigations, threat hunting, and attack research into effective detections.

  • Analyze false positives, false negatives, and detection gaps.

  • Improve detection coverage and map detections to MITRE ATT&CK techniques.

  • Develop and optimize SPL queries, dashboards, reports, and risk-based detections.

  • Define requirements for logging, parsing, normalization, enrichment, and data quality.

  • Develop monitoring and health checks for detection rules and data sources.

  • Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.

  • Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.

  • Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.

  • Document detection logic, data sources, dependencies, limitations, and expected behavior.

Required Experience:
  • Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.

  • Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.

  • Strong proficiency in Splunk SPL or another enterprise SIEM platform.

  • Experience developing complex queries, correlations, dashboards, and reports.

  • Practical experience tuning detections and managing exceptions and allowlists.

  • Ability to define and evaluate logging and telemetry requirements.

  • Proficiency in Python, PowerShell, or Bash for automation.

  • Experience with Git, code reviews, APIs, and basic CI/CD practices.

  • Understanding of Windows and Linux security monitoring.

  • Ability to independently investigate complex problems and drive solutions to completion.

  • Strong communication skills and the ability to work effectively across teams.

Nice to have:
  • Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.

  • Experience with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.

  • Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.

  • Experience building detection quality metrics and automated validation frameworks.

  • Experience with Terraform, Ansible, or other infrastructure-as-code tools.

  • Participation in security research, conferences, or the broader security community.

Our technology focus:

Splunk Enterprise Security, MITRE ATT&CK, Windows and Linux telemetry, Kubernetes and container logs, Python, PowerShell, Bash, Git, and CI/CD.

Our Benefits:
  • Private health insurance

  • Sports benefits

  • Comprehensive Mental Health Program

  • Free English lessons (online)

  • Local language courses

  • Paid time off

  • Maternity leave support

  • Referral program rewards

  • Upskilling, internal workshops, and participation in professional conferences and corporate events

Similar Jobs

3 Days Ago
In-Office or Remote
Senior level
Senior level
Blockchain • Gaming • Payments • Software
Designs, scales, secures, and optimizes distributed cloud infrastructure and deployment pipelines. Responsibilities include managing multi-tenant Kubernetes platforms, Helm templates, CI/CD reliability, release gates, secrets, vulnerability scanning, observability systems, and internal tooling. The role advises development teams on architecture, traffic routing, resource optimization, instrumentation, and service reliability while supporting multi-cloud and multi-region environments.
Top Skills: Api GatewaysBashCi/CdDistributed TracingGoHelmInfrastructure As Code (Iac)IngressKubernetesLinuxLlm FrameworksLoad BalancersLoggingMetricsMlopsMulti-CloudMulti-Region ArchitecturesPythonService MeshesSlasSlisSlosSoftware Composition Analysis (Sca)
4 Days Ago
In-Office or Remote
Junior
Junior
Blockchain • Gaming • Payments • Software
Prepare, localize, configure, publish, and quality-check content across CMS and Back Office systems. Coordinate multilingual content versions, manage promotional mechanics, verify settings and display, and identify or escalate errors. The role requires strong organization, attention to detail, independent decision-making, and the ability to manage multiple deadlines in a dynamic environment.
Top Skills: Back Office SystemsCmsCrm SystemsGoogle SheetsHTMLJIRAJSONSlack
4 Days Ago
In-Office or Remote
Entry level
Entry level
Blockchain • Gaming • Payments • Software
Tests backend services, React applications, APIs, integrations, asynchronous workflows, and end-to-end functionality. Designs manual and automated test coverage using Java or TypeScript and tools such as Playwright, Cypress, or Selenium. Writes complex SQL queries, validates Kafka or RabbitMQ message-driven integrations, investigates defects, analyzes test results, and collaborates with developers and automation QA teams to improve software quality and reliability.
Top Skills: CypressDatabasesJavaKafkaPlaywrightRabbitMQReactSeleniumSQLTypescript

What you need to know about the Edinburgh Tech Scene

From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account