Threat Detection and Response Expert - Blue Team

AI overview

Contribute to improving threat detection capabilities using SIEM and XDR tools while collaborating cross-functionally and training new analysts.

The Threat Detection and Response (TDR) Expert is part of the Blue Team of OBRELA and is responsible for developing, tuning, and maintaining detection capabilities within the organization's security infrastructure. This role focuses on identifying, analyzing, and mitigating security threats using tools like SIEM, XDR, and other detection platforms. The engineer collaborates with cross-functional teams to ensure robust threat detection and response mechanisms.

The TDR Expert also serves as detection authority for initial incident declaration and approves/performs further investigation of escalated events utilizing MDR technologies. Contributes with ideas to improve detection capability and drives recommendations to customers for incident remediation. Assists in the training of new analysts and their further guidance in areas of expertise. Continuously interacts with the SOC for the ongoing improvement of detection and performance metrics.

The TDR Expert is responsible for building and maintaining different SIEM/XDR content libraries and perform R&D for updating the respective content registries. Interacts with the SecDevOps teams or contributes as part of the Blue Team effort to implement threat detection analytics or customer specific use cases.

Requirements:

  • Bachelor’s degree or higher in computer science or related area of study or equivalent combination of education and/or relevant work experience. MSc in relative areas is considered a plus.
  • Experience in rule creation for at least one of the two following SIEMs (IBM QRadar - Azure KQL)
  • Excellent verbal and written communication skills, both in English and Greek language.
  • Problem solving skills on short timeframes and ability to “think outside the box” & Analytical thinking with the ability to break down a big problem into smaller chunks.

Desired requirements:

  • Experience in incidents’ analysis and rule creation using XDR products (CrowdStrike, Palo Alto Cortex, MS Defender)
  • Related certifications (GCIH, GCFE, GCFA, GNFA, eCIR, CEH and/or Security+)
  • Situational assessment and decision-making capabilities

Benefits:

  • Dynamic and respectful environment – our people are the core of our business, we value each and every individual and support initiatives, promoting agility and work/life balance.
  • Continuous coaching – work with passionate people and receive both theoretical as well as hands-on training.
  • Career development. Expand your career internationally and work alongside knowledgeable people from diverse cultures and backgrounds.
  • A competitive compensation package dependent upon your experience and qualifications. We’re focused on rewarding efforts. Our salaries and benefits package will keep you motivated throughout your career.

Perks & Benefits Extracted with AI

  • Career development opportunities: Career development. Expand your career internationally and work alongside knowledgeable people from diverse cultures and backgrounds.

Since our establishment, we’ve set out to transform the way organizations perceive and buy cyber security. Today, we provide the most advanced, comprehensive real time cyber risk management and early warning services.We deliver what we define as Cyber Risk Management as a Service, a comprehensive 360 security program powered by our unique, purpose-built Cyber Risk Management Platform, Swordfish, which integrates in real time, threat detection with detailed risk management and also enables complete vulnerability management.With engagements that include financial institutions, telecommunications, critical infrastructure and on-line service providers, Obrela Security Industries collects and analyses structured and unstructured data, generating valuable intelligence for new, emerging and advanced security threats giving its customers a unique advantage in predictability, preparation and response.If you are ready to work in one of the most challenging corporate security environments, the most demanding clients and be a part of our dream team then apply. We look for hard working, motivated, brilliant out of the box thinking minds that want to become a part of an elite team and work for the most demanding global 500 clients keeping their business in business.We offer exposure in complex enterprise environments helping the most demanding high profile clients develop and sustain their operational security capability.

View all jobs
Report this job

This job is no longer available