Required Skills
SIEM/SOAR
Strong knowledge of SIEM operating principles
Hands-on experience with Splunk and Regex search syntax
Practical experience with TheHive or similar platforms
Systems/Networks
Solid understanding of network and system architectures
Knowledge of intrusion detection probes and event log correlation tools
Security
Strong knowledge of the MITRE ATT&CK framework and associated countermeasures
Proficiency in information monitoring, analysis tools, and methods
Familiarity with security standards across technologies such as web servers, messaging, databases, DNS, proxies, and firewalls
Expertise in one or more of the following areas:
Web application vulnerabilities
Malware families (rootkits, ransomware, botnets, etc.)
Obfuscation and persistence techniques (e.g., cryptography, packing)
Digital forensics and investigation tools
Sandbox behavioral analysis