Skills, qualifications and experience we look for
• Experience: 3+ years of hands-on security engineering experience with demonstrable depth in security operations (SIEM, IR, SOAR, detection engineering, threat hunting).
• Builder Mentality: Proven ability to build security infrastructure from zero, including tool selection, baseline configuration, and policy definition without relying on legacy runbooks.
• Technical Depth: Strong working knowledge of the MITRE ATT&CK framework, custom log source integration, and incident severity matrix mapping.
• SLA & IR Proficiency: Extensive experience managing incident response lifecycles and tuning workflows to meet strict MTTD/MTTR SLAs.
• Compliance Familiarity: Working knowledge of SOC 2 Type II control requirements—specifically CC7 (Monitoring & Detection)—and the operational evidence standards expected by a third-party auditor.
• AI Fluency: Routinely uses LLMs (ChatGPT, Claude, etc.) as part of daily security workflows for alert summarization, rule generation, or automation. Note: You will be asked to demo your AI usage from the last two weeks during the interview process.