Live opening · Posted 11 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Responsibilities
- Design and maintain enterprise SIEM/XSIAM architecture.
- Onboard and optimise endpoint, identity, network, cloud and SaaS telemetry.
- Develop and tune correlation and behavioural detections.
- Use MITRE ATT&CK and threat modelling to identify detection gaps.
- Investigate complex incidents and reconstruct attack timelines.
- Build SOAR playbooks for automated investigation and response.
- Integrate XSIAM with Splunk, Sentinel, ServiceNow and other security tools.
- Improve alert quality, reduce false positives and monitor telemetry health.
Skills
- Strong SIEM/XDR/XSIAM engineering experience.
- Hands-on experience with Cortex XSIAM/XDR preferred.
- Experience with Splunk, Microsoft Sentinel or similar SIEM platforms.
- Strong knowledge of endpoint, identity, cloud and network security telemetry.
- Experience with detection engineering, SOAR and incident response.
- Knowledge of MITRE ATT&CK, Python/PowerShell and REST APIs.
- Strong troubleshooting and analytical skills.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.