Search Jobs

Search by job, company or skills

Security Analyst (AI SOC)

Security Analyst (AI SOC)

qualgo technologies vietnam
  • Posted 8 hours ago
  • Be among the first 10 applicants

Job Description

Qualgo Technologies is seeking a skilled and motivated Cybersecurity Analyst to join our team in building a cybersecurity ecosystem that addresses critical security needs and helps SMEs, businesses, and individuals stay safe online. 

You will develop security monitoring, detection, and automation capabilities across our ecosystem, powered by a dedicated backend, AI LLMs, and Model Context Protocol (MCP) integrations. 

Key Responsibilities: 

  • Develop security data collection, parsing, normalization, and enrichment mechanisms across endpoint, network, cloud, and application sources. 
  • Consume and process security data using Kafka, ClickHouse, S3, and Apache Flink in collaboration with backend engineers. 
  • Develop and optimize detection rules, correlation logic, and investigation workflows based on SIEM concepts. 
  • Build security automation through backend services, APIs, AI LLMs, and MCP integrations. 
  • Apply MITRE ATT&CK and MITRE D3FEND to develop and validate detection and incident response playbooks. 
  • Integrate threat intelligence, security tools, ticketing, and collaboration systems to support investigation and response. 
  • Work with SecOps, Engineering, and Product teams to deliver practical security capabilities for SME customers. 

Skills & Knowledge: 

  • Strong understanding of security monitoring principles and SOC operations. 
  • Proven experience in deploying and managing SIEM platforms (e.g., Splunk, Elastic Security, QRadar, Microsoft Sentinel). 
  • Working knowledge of Kafka, ClickHouse, S3, and Apache Flink, with the ability to consume, query, and process security data. 
  • Familiarity with log formats, collection methods such as Syslog and APIs, and data parsing techniques. 
  • Experience with Python, SQL, and API integrations. 
  • Understanding of automation workflows, including triggers, conditions, retries, error handling, and approval controls. 
  • Familiarity with AI LLMs and MCP concepts for security automation. 
  • Knowledge of MITRE ATT&CK, MITRE D3FEND, and threat intelligence. 
  • Understanding of network protocols, Windows, Linux, and cloud environments such as AWS, Azure, or GCP. 
  • Strong troubleshooting, documentation, and communication skills. 

Experience Requirements: 

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. 
  • Minimum of 3 years of experience in cybersecurity, with a focus on SOC operations, SIEM administration, endpoint security, security automation. 
  • Proven experience in at least one major SIEM platform implementation and management. 
  • Demonstrated experience building integrations or automation through code and APIs. Experience with tools such as n8n is transferable, but n8n is not part of our current stack or a requirement. 
  • Experience integrating security tools and platforms using APIs. 

Professional Certifications (Preferred): 

  • CompTIA Security+, CySA+, CASP+ 
  • GIAC certifications (e.g., GCIH, GCIA, GSEC) 
  • Certified Information Systems Security Professional (CISSP) 

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Automation workflows

MITRE D3FEND

ClickHouse

MITRE ATT CK

Data parsing techniques

Security monitoring principles

AI LLMs

MCP concepts

API integrations

Windows