Sobre este puesto de Senior SOC Engineer en Uni Systems
We are continuously growing and we are looking for a Senior SOC Engineer to join our UniQue Security & Compliance Services team, part of our Professional Services Department.
What will you be bringing to the team?
This is a key technical role responsible for supporting the design, implementation, integration, operation, and ongoing evolution of the company’s Security Operations Center.
We are looking for a hands-on cybersecurity professional with solid experience in SOC engineering, security-platform administration, detection engineering, security integrations, automation, and technical support for incident investigations.
The ideal candidate will contribute to the initial build of the SOC and will retain long-term technical ownership for the health, reliability, configuration, tuning, and continuous improvement of the underlying security technologies.
The role will work closely with SOC Analysts, the SOC Analyst Supervisor, Incident Response, Threat Intelligence, infrastructure, network, cloud, and application teams to ensure that relevant systems are correctly integrated, monitored, and supported.
For the Senior SOC Engineer position we expect you to:
- Support the technical architecture, design, implementation, and operational setup of the Security Operations Center.
- Deploy, configure, integrate, administer, maintain, upgrade, and troubleshoot SOC and cybersecurity technologies.
- Engineer and support SIEM, SOAR, EDR/XDR, NDR, vulnerability-management, threat-intelligence, email-security, and network-security platforms.
- Integrate endpoint, identity, infrastructure, network, cloud, SaaS, application, and business-system data sources using APIs, syslog, agents, collectors, and cloud-native connectors.
- Design and maintain log-source onboarding standards, parsing, normalization, enrichment, retention, health monitoring, and data-quality controls.
- Develop, implement, test, document, and optimise detection rules, correlation logic, analytics, dashboards, reports, watchlists, and monitoring use cases.
- Map detection content to MITRE ATT&CK and validate coverage against relevant attack techniques and business risks.
- Perform technical tuning to reduce false positives, duplicate alerts, and unnecessary noise while preserving or improving detection coverage.
- Work with the SOC Analyst Supervisor and analyst team to translate operational feedback, incident findings, and investigation pain points into engineering improvements.
- Develop and maintain SOAR playbooks, API integrations, scripts, and automated workflows for enrichment, triage, containment, notification, and case management.
- Monitor platform health, connector status, ingestion, licensing, performance, capacity, availability, and security-control effectiveness.
- Provide L2/L3 technical support for complex investigations, security-platform issues, high-severity incidents, and advanced escalations.
- Support threat hunting, malware and telemetry analysis, incident response, root-cause analysis, and post-incident technical improvements.
- Maintain technical documentation, architecture diagrams, configuration baselines, build procedures, support runbooks, and change records.
- Coordinate with infrastructure, network, cloud, identity, and application teams to resolve telemetry gaps and implement required security controls.
- Contribute to technology evaluations, proof-of-concept activities, platform migrations, upgrades, and the continuous maturity of SOC capabilities.
Requirements
Your experience, skillset, and qualifications will help you succeed in this position and grow with the team.
- Bachelor’s degree in Cyber Security, Information Technology, Computer Science, Engineering, or a related field.
- A Master’s degree in Information Security or a related discipline will be considered a plus.
- At least 5 years of proven professional experience in cybersecurity, including a minimum of 3 years of hands-on experience within a SOC environment, covering SOC engineering, security operations, incident response, or related security engineering activities.
- Proven experience implementing, administering, integrating, or supporting SOC technologies in enterprise or managed-service environments.
- Strong hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, or equivalent technologies.
- Experience with SOAR platforms, security orchestration, automated enrichment, incident workflows, and API-based integrations.
- Strong experience with EDR/XDR technologies, preferably CrowdStrike Falcon, Palo Alto Cortex XDR, Microsoft Defender XDR, or similar platforms.
- Experience with Palo Alto Networks firewalls, Panorama, Cortex technologies, or comparable network-security platforms.
- Familiarity with NDR, IDS/IPS, vulnerability-management, email-security, threat-intelligence, and case-management technologies.
- Strong knowledge of security monitoring, detection engineering, alert tuning, incident investigation, threat hunting, and technical escalation practices.
- Experience onboarding and troubleshooting log sources through syslog, APIs, agents, collectors, and cloud-native connectors.
- Good understanding of Windows, Linux, Active Directory, Microsoft 365, identity platforms, networking, DNS, proxies, VPNs, and common network protocols.
- Familiarity with Microsoft Azure, AWS, or other cloud environments and their native security-monitoring capabilities.
- Good understanding of MITRE ATT&CK, attacker tactics and techniques, and common scenarios such as phishing, malware, credential theft, lateral movement, command-and-control, and data exfiltration.
- Scripting and automation experience using Python, PowerShell, Bash, KQL, SPL, or similar languages and query technologies.
- Relevant industry certifications will be highly appreciated, such as Microsoft SC-200 or AZ-500, Palo Alto Networks, CrowdStrike, Splunk, IBM QRadar, GIAC, CompTIA CySA+ or Security+, or other vendor-specific certifications related to SIEM, XDR, cloud security, automation, and incident response.
- Strong troubleshooting, analytical, technical documentation, and problem-solving skills.
- Ability to communicate complex technical concepts and collaborate effectively with analysts, engineering teams, clients, vendors, and business stakeholders.
- Excellent written and verbal communication skills in English.
Benefits
What are we offering to our UniQue IT People?
- People-first approach and open environment to express your ideas
- Work-life balance and a hybrid work model
- Continuous training and development
- Opportunities to join innovation initiatives
- Ticket restaurant – meal vouchers
- Corporate laptop and equipment
- Corporate mobile phone subscription
- Health and insurance plan for you and your family members
- Employee consulting and guidance support
- Discounts on the services and products of our Group’s companies
- Gift vouchers for major life milestones
- Special work schedule on summer Fridays and birthdays
Our UniQue IT people are the most valuable part of Uni Systems; their knowledge and experience have made us the leading and reliable systems integrator of today and have contributed to our steady financial growth. We have created and are maintaining a stable working environment for our employees, with countless opportunities to innovate and thrive. Our work culture recognizes our UniQue IT people and supports the free sharing of ideas and the flow of information via open communication while appreciating and effectively utilizing the talents, skills, and perspectives of each employee.
At Uni Systems, we are providing equal employment opportunities and banning any form of discrimination on grounds of gender, religion, race, color, nationality, disability, social class, political beliefs, age, marital status, sexual orientation or any other characteristics. Take a look at our Diversity, Equality & Inclusion Policy for more information.