Skip to content

Open nowPosted 15 days ago

SOC Detection Engineer – Senior

softswiss65 open roles

Where
T'bilisi, Georgia
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSOC Detection Engineer – Seniorsoftswiss · T'bilisi, Georgia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on softswiss's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market. softswiss postings stay open a median of 1 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 15 days ago

softswiss median: 1 days open

The posting

Overview:

SOFTSWISS is hiring a Senior SOC Detection Engineer to join our Security Operations team. We are seeking a hands-on security professional to help build and develop our detection engineering function, strengthening the company’s ability to identify, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments.

Purpose of the role:

You will be responsible for owning the full lifecycle of security detections, from researching attack techniques and defining logging requirements to developing, testing, deploying, and continuously improving detection content in Splunk. Your work will help enhance detection coverage, improve telemetry quality, reduce false positives, and ensure that security teams can reliably identify and respond to real threats.

Key responsibilities:

  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.
  • Translate incident investigations, threat hunting, and attack research into effective detections.
  • Analyze false positives, false negatives, and detection gaps.
  • Improve detection coverage and map detections to MITRE ATT&CK techniques.
  • Develop and optimize SPL queries, dashboards, reports, and risk-based detections.
  • Define requirements for logging, parsing, normalization, enrichment, and data quality.
  • Develop monitoring and health checks for detection rules and data sources.
  • Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.
  • Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.
  • Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.
  • Document detection logic, data sources, dependencies, limitations, and expected behavior.

Required Experience:

  • Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.
  • Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.
  • Strong proficiency in Splunk SPL or another enterprise SIEM platform.
  • Experience developing complex queries, correlations, dashboards, and reports.
  • Practical experience tuning detections and managing exceptions and allowlists.
  • Ability to define and evaluate logging and telemetry requirements.
  • Proficiency in Python, PowerShell, or Bash for automation.
  • Experience with Git, code reviews, APIs, and basic CI/CD practices.
  • Understanding of Windows and Linux security monitoring.
  • Ability to independently investigate complex problems and drive solutions to completion.
  • Strong communication skills and the ability to work effectively across teams.

Nice to have:

  • Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.
  • Experience with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.
  • Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.
  • Experience building detection quality metrics and automated validation frameworks.
  • Experience with Terraform, Ansible, or other infrastructure-as-code tools.
  • Participation in security research, conferences, or the broader security community.

Our technology focus:

Splunk Enterprise Security, MITRE ATT&CK, Windows and Linux telemetry, Kubernetes and container logs, Python, PowerShell, Bash, Git, and CI/CD.

Our Benefits:

  • Private health insurance
  • Sports benefits
  • Comprehensive Mental Health Program
  • Free English lessons (online)
  • Local language courses
  • Paid time off
  • Maternity leave support
  • Referral program rewards
  • Upskilling, internal workshops, and participation in professional conferences and corporate events
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against softswiss's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on softswiss's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    softswiss's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.