Incident Response & SOC Engineer
Detect, triage, and contain threats against financial systems , from API abuse and credential stuffing to BEC and ransomware , while maintaining pristine audit trails .
Key Responsibilities
- Build / maintain SIEM detections (Splunk / Sentinel / QRadar) mapped to MITRE ATT&CK and financial use-cases.
- Correlate security + business signals (e.g., fraud spikes following auth anomalies).
- Orchestrate containment (token revocation, API key rotation, network isolation) via SOAR.
- Lead forensics / evidence handling , post-incident reporting, and regulator-ready narratives.
- Run threat hunts on high-value assets (payment hubs, API gateways).
Required Skills
SIEM / SOAR engineering, EDR / IDS, threat intel.Financial sector threat landscape knowledge.IR certifications (GCIA, GCIH, GNFA) preferred.