SR INFORMATION SECURITY ENGINEER
About the Role
We are hiring a Senior Information Security Engineer to design, build, automate, operate, and continuously improve the security platforms that power modern Managed Security Services Provider (MSSP) Security Operations Centre services.
This is a senior hands-on engineering role for someone who can take end-to-end ownership of platforms across SIEM, XDR, SOAR, security data pipelines, threat intelligence, cloud security, identity protection, exposure management, and SecOps automation.
In one sentence: Own and engineer the end-to-end MSSP security platform ecosystem to deliver scalable, automated, resilient, and measurable 24x7 SOC services.
What You Will Do
Platform Architecture & Engineering
· Design and implement MSSP-grade security platform architectures for multi-customer SOC service delivery.
· Engineer unified SecOps capabilities across SIEM, XDR, SOAR, EDR, NDR, cloud security, identity security, threat intelligence, ITSM, vulnerability, and exposure management platforms.
· Develop reference architectures, integration standards, data flow diagrams, onboarding patterns, and engineering guardrails.
· Design for resilience, availability, maintainability, scalability, and secure service operation.
SIEM, Security Data Pipelines & Telemetry
· Build and maintain reliable telemetry ingestion using agents, collectors, syslog, CEF/LEEF, APIs, event hubs, forwarders, cloud connectors, custom connectors, OpenTelemetry where applicable, and event streaming platforms.
· Develop parsing, normalization, schema mapping, enrichment, routing, filtering, retention, archival, and data quality controls.
· Prioritize critical security telemetry across endpoint, identity, cloud, SaaS, email, firewall, proxy, VPN, DNS, server, application, and database sources.
· Monitor ingestion health, data volume, parser quality, delayed or missing data, connector failures, duplication, query performance, and storage/licensing usage.
· Optimize ingestion cost and retention strategy without reducing required detection and investigation visibility.
SOAR, Automation & AI-Assisted SecOps
· Design and implement SOAR playbooks for enrichment, triage, escalation, evidence collection, notification, reporting, and case management.
· Integrate security platforms using REST APIs, webhooks, scripts, connectors, service principals, certificates, managed identities, and secure secrets handling.
· Automate repeatable SOC workflows such as phishing triage, suspicious sign-in response, IOC enrichment, endpoint containment support, case creation, and SLA tracking.
· Apply human-in-the-loop controls for high-impact response actions such as account disablement, endpoint isolation, firewall blocking, and production containment.
· Support AI-assisted SecOps workflows, such as investigation summaries, natural language search, analyst assistance, detection support, and playbook development support, with appropriate governance and validation.
Detection Engineering Enablement
· Work with SOC analysts, threat hunters, and detection engineers to deploy, validate, tune, and maintain detection content across SIEM, XDR, EDR, cloud, identity, and network platforms.
· Support MITRE ATT&CK-aligned detection coverage, telemetry gap analysis, threat-informed defence, and purple-team validation.
· Enable Detection-as-Code practices, including version control, peer review, testing, deployment, rollback, and reusable detection content libraries.
· Support detection formats and query languages such as KQL, SPL, XQL, Sigma, YARA, YARA-L, or similar where applicable.
Platform Lifecycle, Patching & Upgrades
· Own lifecycle management for SOC platforms, endpoint agents, cloud agents, collectors, forwarders, connectors, integrations, certificates, API credentials, and supporting infrastructure.
· Plan and execute agent patching, collector upgrades, connector updates, integration maintenance, and platform version upgrades across SIEM, XDR, SOAR, EDR, NDR, CNAPP, CSPM, vulnerability, and related security platforms.
· Perform pre-upgrade assessment, compatibility checks, dependency mapping, change preparation, test planning, rollback planning, maintenance coordination, and stakeholder communication.
· Validate post-upgrade functionality for log ingestion, alert generation, dashboards, playbooks, APIs, ticketing workflows, RBAC, reporting, and customer-specific service outcomes.
· Maintain upgrade roadmaps and documentation to keep platforms secure, stable, supported, scalable, and service-ready.
Customer Onboarding & Service Transition
· Lead technical onboarding for new MSSP customers from discovery and design through integration, testing, acceptance, and SOC handover.
· Create onboarding plans, data flow diagrams, collector designs, integration checklists, validation test cases, runbooks, reporting requirements, and acceptance criteria.
· Work with customer IT, network, cloud, endpoint, identity, application, compliance, and vendor teams to enable required telemetry and controlled response workflows.
· Ensure each customer onboarding includes health checks, ownership, alert routing, severity mapping, escalation process, reporting, and operational readiness.
What You Will Bring
· 5+ years of cybersecurity engineering, security platform engineering, SOC engineering, security data engineering, or security infrastructure experience.
· 3+ years of hands-on experience designing, deploying, maintaining, or upgrading SIEM and/or SOAR platforms in an enterprise, MSSP, MDR, SOC, or security consulting environment.
· Hands-on experience with at least one major SIEM platform such as Microsoft Sentinel, Splunk, Cortex XSIAM, Google SecOps,FortiSIEM, QRadar, or equivalent.
· Hands-on experience with at least one SOAR or automation platform such as Cortex XSOAR, FortiSOAR, Splunk SOAR, MicrosoftSentinel automation, Azure Logic Apps, Google SecOps SOAR, or equivalent.
· Experience with agent deployment and patching, collector and forwarder management, connector updates, platform upgrades, change control, rollback planning, and production validation.
· Strong understanding of security telemetry across cloud, SaaS, identity, endpoint, network, application, database, and infrastructure environments.
· Working knowledge of APIs, scripting, automation, secrets handling, service principals, certificates, secure integration design, and production support practices.
· Strong troubleshooting capability across source devices, agents, collectors, network paths, parsers, ingestion pipelines, storage, dashboards, alerts, playbooks, and ticketing integrations.
· Ability to produce clear architecture diagrams, technical documentation, runbooks, onboarding artefacts, and stakeholder-ready explanations.
Preferred Certifications
· Microsoft SC-200, SC-100, AZ-500, or equivalent Microsoft security certifications.
· Splunk Admin / Architect, Palo Alto Cortex XSOAR or XSIAM, Fortinet NSE, Google SecOps, or other platform certifications.
· GIAC certifications such as GCIA, GCIH, GCFA,GDAT, GCTI, or equivalent practitioner certifications.
· CISSP, CCSP, AWS Security Specialty, or cloud/security architecture certifications.
· Training or practical experience in MITREATT&CK, detection engineering, threat hunting, purple teaming, cloud security, platform engineering, or DevSecOps.
What Success Looks Like
· Security platforms, agents, collectors, connectors, and integrations remain healthy, supported, and operationally reliable.
· Critical telemetry is consistently onboarded, validated, enriched, monitored, and available for detection and investigation.
· Platform upgrades and patching are completed safely with clear validation, rollback planning, and minimal service disruption.
· SOAR and AI-assisted workflows reduce manual effort, improve consistency, and support faster triage and response.
· Detection content is tested, tuned, version-controlled, operationally useful, and aligned to relevant threat behaviors.
· New customer environments are transitioned into SOC operations with validated telemetry, documented architecture, and agreed runbooks.
· Platform health, detection coverage, automation coverage, cost, and service improvement metrics are measurable and reportable.
Why Join This Role
· Work on the engineering foundation of modern MSSP SOC services rather than only operating individual tools.
· Shape scalable platforms across SIEM, XDR, SOAR, cloud, identity, automation, AI-assisted SecOps, and security data engineering.
· Partner with SOC analysts, threat hunters, cloud teams, customers, and vendors to build practical, measurable security outcomes.
· Drive high-impact improvements in automation, telemetry reliability, detection quality, platform resilience, and customer onboarding.
Equal Opportunity
We are committed to building an inclusive workplace and encourage qualified candidates from diverse backgrounds to apply. Selection will be based on the skills, experience, and capabilities relevant to the role.

