📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Security Operation Center L2 Engineer

CoreStar · District de Limassol

New
Mid 🇬🇧 English
Splunk Elastic MITRE ATT&CK Incident response Data engineering

Job description

About the role

CoreStar is looking for an experienced L2 SOC Engineer to become the technical backbone of its Security Operations Center. You will own log source onboarding, design detection processes, and lead incident response for escalated security events while collaborating with IT, DevOps, and NOC teams.

Key responsibilities

  • Onboard new log sources into the SIEM, handling parsing, field extraction, normalization, and enrichment.
  • Design, build, and maintain log pipelines, dashboards, alerts, and detection rules.
  • Identify and close log coverage gaps across endpoint, network, cloud, identity, and application layers.
  • Optimize log volume, retention, and cost within the SIEM platform.
  • Document and continuously improve SOC operating procedures, escalation matrices, and playbooks.
  • Develop detection use cases aligned with MITRE ATT&CK and track SOC KPIs such as MTTD and MTTR.
  • Serve as the primary escalation point for incidents, leading investigation, containment, eradication, and recovery.
  • Perform log correlation, timeline reconstruction, and root‑cause analysis using SIEM and supporting tools.
  • Coordinate with IT, DevOps, NOC, and business stakeholders during active incidents and produce detailed post‑incident reports.

Required profile

  • 3–5+ years of experience in a SOC or security operations role, with progression to an L2 level.
  • Proven experience using AI for SOC automation and detection.
  • Hands‑on expertise with SIEM platforms and log data engineering.
  • Strong knowledge of incident response processes and MITRE ATT&CK framework.

Required skills

  • SIEM platforms such as Splunk, Microsoft Sentinel, IBM QRadar, Elastic.
  • AI/ML techniques applied to security automation.
  • Log parsing, field extraction, normalization, and enrichment.
  • Design and maintenance of detection rules, dashboards, and alerts.
  • MITRE ATT&CK framework.
  • Incident response lifecycle (investigation, containment, eradication, recovery).
  • Data engineering for security telemetry.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec CoreStar.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Cyprus.

Salaries by job title

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 3 days ago

Expires 1 month from now

13 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

CoreStar

District de Limassol