SIEM & SecOps Engineer II
TLDR
Build and tune enterprise SIEMs and detection content to detect, investigate, and respond to threats across complex banking platforms.
-
Design, develop, and maintain high-fidelity detection rules, correlation rules, alerts, and security use cases for newly onboarded and existing log sources. Continuously tune detections to reduce false positives, improve detection fidelity, and expand detection coverage across the environment.
-
Develop security monitoring and detection content for AWS services, Kubernetes, microservices, Linux, macOS, databases, web applications, firewalls, and other enterprise technologies by leveraging the MITRE ATT&CK framework, threat intelligence, and adversary TTPs.
-
Onboard new security and application log sources by developing Logstash pipelines, custom parsers, Grok patterns, ingest processors, and enrichment workflows. Analyze raw log formats, normalize events to a common schema, and enrich security telemetry to enable reliable detection and investigation.
-
Design and maintain operational dashboards, executive dashboards, SOC dashboards, and threat hunting visualizations using optimized OpenSearch Query DSL, aggregations, and visualizations to provide actionable security insights and platform observability.
-
Integrate Threat Intelligence Platforms (TIP), IOC feeds, and enrichment services with OpenSearch. Develop IOC correlation rules, automated enrichment workflows, and contextual detections to identify malicious activity across ingested telemetry.
-
Expand the SIEM by implementing advanced capabilities such as UEBA, anomaly detection, OpenSearch Notebooks for investigation playbooks, SOAR workflows for automated response, and AI-driven automation to streamline Level 1 SOC operations.
-
Collaborate with SOC analysts during alert investigations, threat hunting, and incident response by providing L2/L3 detection engineering support, validating detections, identifying detection gaps, and continuously improving existing security content.
-
Follow Detection-as-Code practices by developing, testing, version-controlling, and deploying detection content through Git-based workflows and CI/CD pipelines, ensuring consistent, reliable, and scalable delivery of SIEM content.
-
Hands-on experience with any enterprise SIEM platforms such as Elastic/ELK, OpenSearch, Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, Google Chronicle, Wazuh, ELK/EFK or similar solutions.
-
Experience developing, maintaining, and tuning detection rules, correlation rules, alerts, dashboards, visualizations, and security use cases using SIEM query languages and detection frameworks such as OpenSearch/Elasticsearch Query DSL, Sigma, KQL, SPL, EQL, or equivalent.
-
Strong experience onboarding log sources by developing custom parsers, Logstash pipelines, Fluentd/Fluent Bit configurations, Grok patterns, ETL pipelines, field mappings, log normalization, and data enrichment workflows.
-
4–6 years of experience in Detection Engineering, SIEM Engineering, Security Operations, or SOC environments.
-
Good understanding of SIEM architecture, event correlation, log management, detection engineering, the MITRE ATT&CK framework, Cyber Kill Chain, threat hunting methodologies, attacker TTPs, Threat Intelligence integration, and IOC-based detections.
-
Experience developing detections and investigating security events across Linux, macOS, databases, web applications, firewalls, WAFs, enterprise infrastructure, and cloud environments.
-
Familiarity with open-source security technologies such as Wazuh, Suricata, Zeek (Bro), Velociraptor, HELK, EFK, Falco, osquery, or similar security monitoring solutions.
-
Strong foundation in computer networking, operating systems, authentication and authorization concepts, web technologies, and common attack techniques.
-
Familiarity with YARA rules, malware detection concepts, and security automation is an added advantage.
-
Strong analytical, troubleshooting, and investigative skills with the ability to identify detection gaps, validate detections, and continuously improve security monitoring content.
-
Hands-on experience with AWS environments and a good understanding of core AWS services such as IAM, CloudTrail, VPC, EC2, EKS, S3, CloudWatch, and cloud security monitoring concepts.
-
Familiarity with Kubernetes, Helm, containerized workloads, microservices architectures, and cloud-native security monitoring, Git, CI/CD Pipeline knowledge etc.
Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success.
Zeta builds cloud-native, fully stackable processing and core banking platforms designed for financial institutions. Our solutions empower issuers to modernize their technology infrastructure and enhance the digital banking experience, seamlessly supporting millions of cards across multiple countries.