Job Description/Specification:
MEEZA is seeking an experienced Security Infrastructure Engineer – MS Sentinel / Google SecOps to support enterprise security infrastructure, SIEM/SOAR platforms, cloud telemetry, automation, and SOC operations.
The successful candidate will manage security data ingestion, develop automated incident-response workflows, maintain integrations, optimize SIEM performance, and collaborate with SOC and infrastructure teams. Strong hands-on experience with Google SecOps (Chronicle), Microsoft Sentinel, Python, cloud security, and security automation is required.
Key Responsibilities
SIEM & Data Engineering
- Architect and maintain security telemetry ingestion from GCP, AWS, Azure, and on-premises environments.
- Manage BindPlane Forwarders, cloud-to-cloud connectors, webhooks, and related ingestion pipelines.
- Develop and troubleshoot custom parsers for non-standard log sources and ensure proper UDM normalization.
- Monitor ingestion rates, latency, data quality, and dropped logs.
- Develop dashboards to monitor platform and data health.
SOAR & Security Automation
- Design and develop automated incident-response playbooks using Python and SOAR tools.
- Build API integrations between SIEM/SOAR platforms and firewalls, EDR, IAM, ticketing, and other security solutions.
- Automate artifact enrichment, evidence collection, containment, and repetitive SOC activities.
- Configure case-management workflows, custom fields, stages, and SLA tracking.
Platform Administration
- Maintain SIEM/SOAR platform availability, performance, and security.
- Manage Role-Based Access Control (RBAC) and analyst permissions.
- Integrate threat intelligence sources such as Mandiant and VirusTotal.
- Support detection engineering and optimization of YARA/YARA-L rules based on SOC feedback.
SOC & Infrastructure Collaboration
- Work with Tier 1 and Tier 2 SOC analysts to improve detections and reduce alert noise.
- Translate incident-response processes into automated SOAR workflows.
- Conduct knowledge-transfer sessions covering UDM Search, Sentinel, and investigation processes.
- Coordinate with GCP, AWS, and Azure teams for cloud logging and telemetry integration.
- Support deployment and maintenance of BindPlane Forwarders.
- Troubleshoot network, connectivity, and firewall issues affecting security telemetry.
Qualifications & Experience
- Bachelor’s degree in Computer Science, IT, Cybersecurity, or a related discipline.
- 3–5 years of experience in Security Engineering, SOC Automation, Security Operations, DevOps, or Infrastructure Security.
- Strong experience managing enterprise SIEM/SOAR platforms such as Microsoft Sentinel, Splunk, or QRadar.
- Minimum 1–2 years of hands-on Google SecOps (Chronicle) experience.
- Microsoft Azure Sentinel/SIEM certification preferred.
- Security+, CySA+, CEH, CISSP, GCIH, or similar security certifications are advantageous.
Technical Skills
- Google SecOps / Chronicle
- Microsoft Sentinel and SIEM/SOAR
- Advanced Python scripting and API integrations
- GCP security, IAM, VPC Service Controls and Cloud Logging
- SQL / BigQuery
- YARA and YARA-L
- Bash scripting
- Git, Terraform, Docker and Kubernetes
- JSON, Protobuf and Regex
- MITRE ATT&CK and NIST Cybersecurity Framework
- Cloud security across Azure, AWS and GCP
Key Competencies
Strong analytical and troubleshooting abilities are essential, along with excellent communication, documentation, and problem-solving skills. Candidates should be comfortable working independently, managing multiple security priorities, and collaborating across SOC, cloud, network, and infrastructure teams.