Lead SOC Engineer (SIEM)
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
About the Role
Overview The Lead Engineer – SOC (SIEM) is a critical role responsible for delivering SIEM management services, particularly focusing on Splunk SIEM and Splunk UEBA, within the Security Operations Center (SOC).
Key Skills for This Role
Full Job Posting
Overview
The Lead Engineer – SOC (SIEM) is a critical role responsible for delivering SIEM management services, particularly focusing on Splunk SIEM and Splunk UEBA, within the Security Operations Center (SOC).
Working closely with the SOC Team this role encompasses onboarding new log sources, enhancing and optimizing telemetry, ensuring system updates, resolving issues, and maintaining SIEM performance, designing SIEM Architecture and deployments based on customized business requirements.
Key Responsibilities
- Deliver and Lead Splunk SIEM management services within the SOC environment.
- Architect scalable and resilient Splunk-based SIEM solutions.
- Define data ingestion strategies, parsing logic, and correlation rules.
- Collaborate with the asset owner, client stakeholder, and SOC, in onboarding new log sources to the SIEM platform.
- Maintain and govern SOC critical log sources, ensuring their proper functionality and integration with Splunk SIEM.
- Detect log source issues, coordinate with customers to diagnose and resolve them in a timely manner.
- Enhance and optimize telemetry within the Splunk environment to improve data collection, correlation, and reporting.
- Collaborate with SOC and threat intelligence teams to develop detection use cases.
- Implement dashboards, alerts, and reports for proactive threat monitoring.
- Perform regular system updates to ensure Splunk functionality and security are up to date.
- Resolve Splunk-related issues promptly and efficiently.
- Proficiency in field extractions, data normalization, and CIM (Common Information Model) compliance.
- Maintain the performance of the Splunk SIEM according to established best practices.
- Participate in continuous process improvements to increase SOC efficiency and effectiveness.
- Provide regular and accurate reports on Splunk services and SOC operations to relevant stakeholders.
- Contribute to SOC architecture strategy and implementation initiatives related to Splunk in the pre-sales phase when required.
- Plan and execute Splunk version upgrades and feature rollouts.
- Evaluate and deploy new Splunk apps and add-ons.
Characterstics
- Profound knowledge and hands-on experience with Splunk SIEM and other related technologies like CRIBL.
- Understanding of SOC workflows, MITRE ATT&CK framework, and threat detection methodologies.
- Ability to correlate data across multiple sources to identify patterns and anomalies.
- Strong understanding of cloud and network technologies, essential for efficient log source onboarding.
- Proven technical capabilities in a complex, fast-paced SOC environment.
- Ability to diagnose and troubleshoot log source issues related to cloud and network infrastructures.
- Strong understanding of SOC operations, cybersecurity principles, and best practices.
- Excellent problem-solving skills and the ability to make decisions under pressure.
- Ability to collaborate effectively with a variety of team members, including interfacing with customers to resolve issues.
- High proficiency in written and verbal communication
Skills & Certificates
- Splunk Certified Architect or Splunk Certified Administrator.
- Mastery of SPL (Search Processing Language) for complex queries, dashboards, and reports.
- Scripting skills (Python, Bash, PowerShell)
- Cloud-related certifications like AWS Certified Solutions Architect, Google Professional Cloud Architect, or Microsoft Certified: Azure Solutions Architect Expert.
- Certified Information Systems Security Professional (CISSP), GIAC is preferred.
- Excellent communication and documentation skills
- Ability to lead technical initiatives and work independently
Education
Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field.
Minimum Work Exp
A minimum of 8 years of experience in SOC operations, with significant experience in Splunk SIEM management
Prior experience in a technical role within a SOC or similar cybersecurity environment.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at CPX
Lead SOC Engineer (OT Cybersecurity)
Abu Dhabi, UAE
Overview Job Purpose OT Detection is a senior technical and engineering leader role focused on designing and implementing advanced threat detection capabilities within OT environments. Operating within CPX’s hybrid Secur
Lead Analyst - SOC Monitoring (CPX)
Abu Dhabi, UAE
Overview The Lead SOC Analyst is responsible for managing the day-to-day activities of the SOC Monitoring, Incident Detection, and Response Operations. The role involves collaborating with internal and client teams to id
Lead Analyst - SOC Monitoring (CPX)
Abu Dhabi, UAE
Overview The Lead SOC Analyst is responsible for managing the day-to-day activities of the SOC Monitoring, Incident Detection, and Response Operations. The role involves collaborating with internal and client teams to id
Senior Specialist – Client Success and Delivery
Abu Dhabi Emirate, UAE
Job Title - Senior Specialist – Client Success and Delivery Years of Experience - 8-10 Years - At Least 4+ Years in a Similar Role Education - Bachelor's in computer science, Computer Engineering, Information Technology,
Lead Consultant - Incident Response (CPX)
Abu Dhabi, UAE
Overview As a Principal Consultant – Incident Response, you live and breathe blue team operations. Your technical expertise in endpoint and network threat detection and defence is complemented by your integrity and passi
Lead Analyst - Sector Domain (OT Cybersecurity)
Abu Dhabi, UAE
Overview OT Lead Analyst Sector Domain is the liaison officer of the sector in OT SOC and vice versa. Communicate activities, decision, etc. to the sector stakeholders. Responsibilities Hold and provide all sector speci
Senior Manager - Alliances and Partnerships (CPX)
Abu Dhabi, UAE
Overview About the Role The Senior Manager – Partnerships & Alliances is responsible for activating, scaling, and monetising CPX’s strategic partner ecosystem to drive measurable revenue, pipeline, and market differentia
Manager - OT Cybersecurity (CPX)
Abu Dhabi, UAE
Overview Securing operational technology (OT), industrial IoT (IIoT), and IoT environments across multiple critical infrastructure sectors, including oil and gas, utilities, manufacturing, mining, and more. Provide consu
Lead SOC Engineer (OT Cybersecurity)
Abu Dhabi, UAE
Lead Analyst - SOC Monitoring (CPX)
Abu Dhabi, UAE
Lead Analyst - SOC Monitoring (CPX)
Abu Dhabi, UAE
Senior Specialist – Client Success and Delivery
Abu Dhabi Emirate, UAE
Lead Consultant - Incident Response (CPX)
Abu Dhabi, UAE
Lead Analyst - Sector Domain (OT Cybersecurity)
Abu Dhabi, UAE
Senior Manager - Alliances and Partnerships (CPX)
Abu Dhabi, UAE
Manager - OT Cybersecurity (CPX)
Abu Dhabi, UAE