Search by job, company or skills

Security Analyst (AI SOC)

Security Analyst (AI SOC)

qualgo technologies vietnam
5-7 Years
Not Disclosed
  • Posted 16 hours ago
  • Be among the first 10 applicants

Job Description

Qualgo Technologies is seeking a skilled and motivated Cybersecurity Analyst to join our team in building a cybersecurity ecosystem that addresses critical security needs and helps SMEs, businesses, and individuals stay safe online.

You will develop security monitoring, detection, and automation capabilities across our ecosystem, powered by a dedicated backend, AI LLMs, and Model Context Protocol (MCP) integrations.

Key Responsibilities:

  • Develop security data collection, parsing, normalization, and enrichment mechanisms across endpoint, network, cloud, and application sources.
  • Consume and process security data using Kafka, ClickHouse, S3, and Apache Flink in collaboration with backend engineers.
  • Develop and optimize detection rules, correlation logic, and investigation workflows based on SIEM concepts.
  • Build security automation through backend services, APIs, AI LLMs, and MCP integrations.
  • Apply MITRE ATT&CK and MITRE D3FEND to develop and validate detection and incident response playbooks.
  • Integrate threat intelligence, security tools, ticketing, and collaboration systems to support investigation and response.
  • Work with SecOps, Engineering, and Product teams to deliver practical security capabilities for SME customers.

Required Qualifications:

  • Strong understanding of security monitoring principles and SOC operations.
  • Proven experience in deploying and managing SIEM platforms (e.g., Splunk, Elastic Security, QRadar, Microsoft Sentinel).
  • Working knowledge of Kafka, ClickHouse, S3, and Apache Flink, with the ability to consume, query, and process security data.
  • Familiarity with log formats, collection methods such as Syslog and APIs, and data parsing techniques.
  • Experience with Python, SQL, and API integrations.
  • Understanding of automation workflows, including triggers, conditions, retries, error handling, and approval controls.
  • Familiarity with AI LLMs and MCP concepts for security automation.
  • Knowledge of MITRE ATT&CK, MITRE D3FEND, and threat intelligence.
  • Understanding of network protocols, Windows, Linux, and cloud environments such as AWS, Azure, or GCP.
  • Strong troubleshooting, documentation, and communication skills.

Experience Requirements:

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of 5 years of experience in cybersecurity, with a focus on SOC operations,
  • SIEM administration, endpoint security, security automation.
  • Proven experience in at least one major SIEM platform implementation and management.
  • Demonstrated experience building integrations or automation through code and APIs. Experience with tools such as n8n is transferable, but n8n is not part of our current stack or a requirement.
  • Experience integrating security tools and platforms using APIs.

Professional Certifications (Preferred):

  • CompTIA Security+, CySA+, CASP+
  • GIAC certifications (e.g., GCIH, GCIA, GSEC)
  • Certified Information Systems Security Professional (CISSP)

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

MITRE D3FEND

ClickHouse

MITRE ATT CK

API integrations

Windows