Logo for SOFTSWISS

SOC Detection Engineer – Senior

Role overview

Qualifications

  • Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field
  • Deep understanding of MITRE ATTCK, common attack techniques, and detection methodologies
  • Strong proficiency in Splunk SPL or another enterprise SIEM platform
  • Proficiency in Python, PowerShell, or Bash for automation

Responsibilities

  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM
  • Translate incident investigations, threat hunting, and attack research into effective detections
  • Analyze false positives, false negatives, and detection gaps
  • Improve detection coverage and map detections to MITRE ATTCK techniques

Key facts

  • Remote from: Georgia (USA)
  • Full time
  • Senior (5-10 years)
  • SOC Analyst
  • English

Hard skills

Other skills

  • Communication
  • Problem Solving

About the company

SOFTSWISS logo

SOFTSWISS

Sports Betting & iGaming

SOFTSWISS is an international company and a widely-acclaimed iGaming expert. We were the very first online gambling software company to start working with cryptocurrencies. SOFTSWISS appeared in July 2009 in Minsk, Belarus. Today SOFTSWISS is a recognised industry leader in iGaming software solutions development. The company has an international team, which counts 1,400+ employees and has an official presence in Poland, Malta, Georgia, and Belarus. To date, the SOFTSWISS client network counts more than 500 iGaming brands. Projects powered by SOFTSWISS receive numerous awards and accolades from industry media. SOFTSWISS steadily enhances the products portfolio with continuous innovations and increases the quality of its services, providing customers with first-class industry solutions. Our values: - High-end solutions based on reliability, security and honesty - Expertise of a professional team with over 10 years of iGaming background - Innovative approach to product development and business processes Our Products: - Sportsbook Platform - Online Casino Platform - Game Aggregator - Jackpot Aggregator - Affilka (Affiliate Platform) - Managed Services Our Services: - First Line Player Support - Player Retention - Player Reactivation - VIP Player Support - Anti-fraud support Our solutions: - Crypto Casino Solution - White Label Casino Solution - Turnkey Casino Solution White Label solutions: - Operating under the SOFTSWISS gambling licences - Ready-to-use payment processing options - SOFTSWISS merchant accounts Why Us? - Over 10 years helping our clients to succeed in the industry - Focus on software security and stability - Top client service based on the client needs - Best industry professionals - Agile methodology at all levels - Cutting-edge innovations - Wide geographical presence Website: www.softswiss.com Email: order@softswiss.com SOFTSWISS. Winning Combination

Company details

Company typeLarge
IndustrySports Betting & iGaming
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Overview:

SOFTSWISS is hiring a Senior SOC Detection Engineer to join our Security Operations team. We are seeking a hands-on security professional to help build and develop our detection engineering function, strengthening the company’s ability to identify, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments.

Purpose of the role:

You will be responsible for owning the full lifecycle of security detections, from researching attack techniques and defining logging requirements to developing, testing, deploying, and continuously improving detection content in Splunk. Your work will help enhance detection coverage, improve telemetry quality, reduce false positives, and ensure that security teams can reliably identify and respond to real threats.

Key responsibilities:

  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.

  • Translate incident investigations, threat hunting, and attack research into effective detections.

  • Analyze false positives, false negatives, and detection gaps.

  • Improve detection coverage and map detections to MITRE ATT&CK techniques.

  • Develop and optimize SPL queries, dashboards, reports, and risk-based detections.

  • Define requirements for logging, parsing, normalization, enrichment, and data quality.

  • Develop monitoring and health checks for detection rules and data sources.

  • Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.

  • Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.

  • Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.

  • Document detection logic, data sources, dependencies, limitations, and expected behavior.

Required Experience:

  • Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.

  • Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.

  • Strong proficiency in Splunk SPL or another enterprise SIEM platform.

  • Experience developing complex queries, correlations, dashboards, and reports.

  • Practical experience tuning detections and managing exceptions and allowlists.

  • Ability to define and evaluate logging and telemetry requirements.

  • Proficiency in Python, PowerShell, or Bash for automation.

  • Experience with Git, code reviews, APIs, and basic CI/CD practices.

  • Understanding of Windows and Linux security monitoring.

  • Ability to independently investigate complex problems and drive solutions to completion.

  • Strong communication skills and the ability to work effectively across teams.

Nice to have:

  • Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.

  • Experience with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.

  • Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.

  • Experience building detection quality metrics and automated validation frameworks.

  • Experience with Terraform, Ansible, or other infrastructure-as-code tools.

  • Participation in security research, conferences, or the broader security community.

Our technology focus:

Splunk Enterprise Security, MITRE ATT&CK, Windows and Linux telemetry, Kubernetes and container logs, Python, PowerShell, Bash, Git, and CI/CD.

Our Benefits:

  • Private health insurance

  • Sports benefits

  • Comprehensive Mental Health Program

  • Free English lessons (online)

  • Local language courses

  • Paid time off

  • Maternity leave support

  • Referral program rewards

  • Upskilling, internal workshops, and participation in professional conferences and corporate events

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

SOC Analyst Related jobs

Other jobs at SOFTSWISS

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.