SOC Analyst, Continuous Improvement
COURBEVOIE, 92
il y a 1 jour
- Enhance detection capabilities
- Design and improve SIEM, EDR, and XDR rules
- Optimize signal quality by reducing false positives and improving relevance
- Develop use cases aligned with current threats
- Design and implement SOAR playbooks
- Automate low-value-added tasks
- Analyze incidents and operational pain points in the Run phase
- Identify opportunities to improve tools and detections
- Turn field feedback into concrete enhancements
- Leverage MITRE ATT&CK and threat intelligence
- Identify blind spots and improve visibility
- Propose innovative use cases
- Document rules, processes, and standards
- Contribute to the SOC’s overall maturity
- Own a detection or automation initiative from requirements analysis through deployment and ongoing monitoring
Requirements
- Master’s degree in Computer Science, Information Technology, or a related field
- Significant experience—4 to 5 years—in creating, improving, and tuning SIEM detection rules and use cases
- Fluent English (reading, writing, and speaking) required
- Responsiveness and attention to detail
- Creation and optimization of detection and correlation rules
- Design and evolution of SOC use cases
- Proficiency in a query/detection language (SPL, KQL, EQL, AQL, Sigma, etc.)
- Scripting/development skills (Python, PowerShell, or Bash)
- Design, use, and maintenance of SOAR playbooks
- Rule tuning and reduction of false positives and alert fatigue
- Use of MITRE ATT&CK
- Threat hunting
- Monitoring of SOC KPIs (alert quality, volumes, false positives, MTTD/MTTR, etc.)
- Ideally: Detection-as-Code, Git, CI/CD, and APIs
- Good knowledge of log sources (EDR, AD/Entra ID, firewalls, proxies, DNS, cloud, endpoints, etc.)
- Ability to own a detection or automation initiative from requirements analysis through deployment and ongoing monitoring
- Open to candidates with disabilities
Core Competencies
Demonstrates expertise in designing and optimizing SIEM, EDR, and XDR detection rules, with a strong focus on reducing false positives and enhancing signal quality. Proficient in leveraging threat intelligence and MITRE ATT&CK to develop innovative use cases and improve SOC maturity.
Highest-signal resume keywords
- SIEM Detection Rule Creation
- Proficiency in Query Languages (SPL, KQL, EQL, AQL, Sigma)
- Scripting Skills (Python, PowerShell, Bash)
- SOAR Playbook Design and Maintenance
- Threat Hunting
Hard Skills
- SIEM Detection Rule Tuning
- Detection and Correlation Rule Optimization
- SOC Use Case Design
- Incident Analysis
- Automation of Low-Value Tasks
Soft Skills
- Attention to Detail
- Responsiveness
Certifications & Qualifications
- Master’s Degree in Computer Science
- Master’s Degree in Information Technology
Industry Keywords
- Threat Intelligence
- SOC Maturity
- Alert Fatigue
- MTTD
- MTTR
Tools & Technologies
- SOAR
- MITRE ATT&CK
- EDR
- Cloud
- Log Sources
Entreprise
Jobtailor
Plateforme de publication
WHATJOBS
Offres pouvant vous intéresser
PARIS, 75
il y a 17 jours
FRANCE
il y a 18 jours
PARIS, 75
il y a 17 jours
PARIS, 75
il y a 17 jours