Verified today
Senior SOC Engineer
About the role
The Senior SOC Engineer role sits within the Cyber Defense Operations Center (CDOC) Detection and Response Engineering team at Metro Global Solution Center (MGSC) in Kharadi, Maharashtra, India, working on-site. You will support SOC Specialists by integrating log sources, developing use cases, and building response playbooks focused on XDR, SIEM, and SOAR technologies. Day-to-day work centers on designing custom parsers, writing integration guides and technical documentation, validating parser outputs, and continuously improving detection logic and alert use cases.
What you’ll do
- Design and build custom parsers for diverse log formats, threat feeds, and telemetry sources.
- Develop integration guides for connecting security tools with external systems such as cloud platforms, identity providers, and ticketing systems.
- Write technical documentation for parser configuration, schema mapping, normalization, and enrichment workflows.
- Test and validate parser outputs to ensure accurate data extraction and ingestion.
- Continuously improve SIEM/SOAR/XDR alert use cases and detection logic.
- Create tutorials and walkthroughs for parser development using Python, Regex, and AI prompts.
- Collaborate with the overall Cyber Defense team to capture use cases, edge cases, and operational needs.
- Maintain integration documentation for REST APIs, webhooks, and SDKs across security platforms.
What you’ll bring
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 4-7 years of total experience in SecOps/DevOps within a large multi-national organization or a known MSSP.
- At least 3 years of working experience in automation, integration, and custom parser creation for SecOps/DevOps tools such as SIEM, SOAR, or ITSM tools.
- In-depth knowledge of custom parsing, Python scripting, REGEX, API Integration, and playbook creation.
- Hands-on expertise in log parsing, data normalization, and custom parser development.
- Proficiency with SIEM platforms, log formats (JSON, Syslog, XML), and parsing tools (Regex, Logstash) and AI prompting.
- Skilled in REST APIs, JSON schemas, and integration workflows.
- Proven experience in technical writing and content creation for security products.
Skills
Education
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.