Security Analyst (AI SOC)
Security Analyst (AI SOC)
qualgo technologies vietnam- Posted 16 hours ago
- Be among the first 10 applicants
Job Description
Qualgo Technologies is seeking a skilled and motivated Cybersecurity Analyst to join our team in building a cybersecurity ecosystem that addresses critical security needs and helps SMEs, businesses, and individuals stay safe online.
You will develop security monitoring, detection, and automation capabilities across our ecosystem, powered by a dedicated backend, AI LLMs, and Model Context Protocol (MCP) integrations.
Key Responsibilities:
- Develop security data collection, parsing, normalization, and enrichment mechanisms across endpoint, network, cloud, and application sources.
- Consume and process security data using Kafka, ClickHouse, S3, and Apache Flink in collaboration with backend engineers.
- Develop and optimize detection rules, correlation logic, and investigation workflows based on SIEM concepts.
- Build security automation through backend services, APIs, AI LLMs, and MCP integrations.
- Apply MITRE ATT&CK and MITRE D3FEND to develop and validate detection and incident response playbooks.
- Integrate threat intelligence, security tools, ticketing, and collaboration systems to support investigation and response.
- Work with SecOps, Engineering, and Product teams to deliver practical security capabilities for SME customers.
Required Qualifications:
- Strong understanding of security monitoring principles and SOC operations.
- Proven experience in deploying and managing SIEM platforms (e.g., Splunk, Elastic Security, QRadar, Microsoft Sentinel).
- Working knowledge of Kafka, ClickHouse, S3, and Apache Flink, with the ability to consume, query, and process security data.
- Familiarity with log formats, collection methods such as Syslog and APIs, and data parsing techniques.
- Experience with Python, SQL, and API integrations.
- Understanding of automation workflows, including triggers, conditions, retries, error handling, and approval controls.
- Familiarity with AI LLMs and MCP concepts for security automation.
- Knowledge of MITRE ATT&CK, MITRE D3FEND, and threat intelligence.
- Understanding of network protocols, Windows, Linux, and cloud environments such as AWS, Azure, or GCP.
- Strong troubleshooting, documentation, and communication skills.
Experience Requirements:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 5 years of experience in cybersecurity, with a focus on SOC operations,
- SIEM administration, endpoint security, security automation.
- Proven experience in at least one major SIEM platform implementation and management.
- Demonstrated experience building integrations or automation through code and APIs. Experience with tools such as n8n is transferable, but n8n is not part of our current stack or a requirement.
- Experience integrating security tools and platforms using APIs.
Professional Certifications (Preferred):
- CompTIA Security+, CySA+, CASP+
- GIAC certifications (e.g., GCIH, GCIA, GSEC)
- Certified Information Systems Security Professional (CISSP)
More Info
Key Skills
MITRE D3FEND
ClickHouse
MITRE ATT CK
API integrations
Windows
