Security Monitoring Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Experteer Overview As a Detection Strategist in AXA’s Security Operations Center, you shape high-fidelity detections by translating attacker behavior into durable rules.You bridge offensive tradecraft with SOC outcomes, owning detection content and guiding telemetry needs to improve visibility.Your work focuses on crafting advanced KQL-based alerts, reducing false positives, and collaborating with incident response to close gaps.This role offers impact at scale within a global, tech-driven security team.Compensaciones / Beneficios * Author complex KQL queries to detect sophisticated behaviors * Analyze raw telemetry from EDR, identity providers, and cloud infra to identify data gaps and improve logging policies * Tune rules to minimize false positives and prevent SOC noise * Validate new detections via targeted validation attacks and technique mapping to MITRE ATTu**CK * Perform gap analyses to uncover blind spots and drive remediation * Translate threat intelligence and red team techniques into actionable detection logic * Review and optimize the detection rule library for accuracy and coverage * Collaborate with Incident Response to understand and prevent recurrence of missed attacks Responsabilidades * Experience as a Red Teamer or in offensive security * Strong knowledge of attacker techniques and how to bypass detections * Ability to author high-fidelity SIEM detections and understand telemetry needs * Hands-on experience with log data from EDR, identity providers, and cloud platforms * Familiarity with MITRE ATTu**CK mapping and validation of detections Requisitos principales *
Requirements
Compensaciones / Beneficios * Author complex KQL queries to detect sophisticated behaviors * Analyze raw telemetry from EDR, identity providers, and cloud infra to identify data gaps and improve logging policies * Tune rules to minimize false positives and prevent SOC noise * Validate new detections via targeted validation attacks and technique mapping to MITRE ATTu**CK * Perform gap analyses to uncover blind spots and drive remediation * Translate threat intelligence and red team techniques into actionable detection logic * Review and optimize the detection rule library for accuracy and coverage * Collaborate with Incident Response to understand and prevent recurrence of missed attacks Responsabilidades * Experience as a Red Teamer or in offensive security * Strong knowledge of attacker techniques and how to bypass detections * Ability to author high-fidelity SIEM detections and understand telemetry needs * Hands-on experience with log data from EDR, identity providers, and cloud platforms * Familiarity with MITRE ATTu**CK mapping and validation of detections Requisitos principales *
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Data Analyst Salary in the UK
Understanding and Mitigating Common Web Vulnerabilities
9 Ways to Make Money Hacking
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents