act digital is an international consulting and engineering group that supports its clients in their digital transformation projects.
Present in 12 countries and with more than 7,000 employees, we leverage our expertise to address their challenges in software development, cybersecurity, data, cloud, and AI.
Our ambition: to become the trusted technology partner of the most innovative companies, by designing and securing systems that enhance their performance and resilience.
Joining act digital means becoming part of an agile and committed organization that works closely with its clients to turn ideas into concrete results, with pragmatism and high standards.
Job Description :You will join our team of experts in cybersecurity.
Your responsibilities will include:
- Contribute to the development, implementation, validation, tuning, and maintenance of security monitoring, analytics, and detection capabilities across SIEM, EDR, cloud, and
other cybersecurity platforms.
- Support the operation, maintenance, optimization, and continuous improvement of security monitoring and threat detection services.
- Participate in the onboarding, integration, testing, and validation of security data sources, telemetry feeds, and monitoring capabilities.
- Contribute to security content management activities, including use case lifecycle management, rule reviews, testing, tuning, and content quality assurance.
- Collaborate with cyber threat intelligence, incident response, and cybersecurity operations teams to translate operational and threat intelligence requirements into effective detection and monitoring capabilities.
- Under guidance, participate in cybersecurity architecture reviews of new or existing solutions and provide recommendations to enhance security monitoring and detection
effectiveness.
- Contribute to the preparation and maintenance of cybersecurity operations metrics, dashboards, KPIs, and service performance reports.
- Review, validate, and assess the effectiveness of detections, monitoring configurations, operational processes, and service deliverables, identifying opportunities for
improvement.
- Gather and analyze operational feedback to identify opportunities for tuning, optimization, reduction of false positives, and improvement of overall detection quality.
- Contribute to quality assurance activities, including process reviews, control validation, service quality assessments, and implementation of corrective actions.
- Support the development, review, and maintenance of CSOC procedures, standards, documentation, knowledge base articles, and operational guidance materials.
- Prepare and present technical reports, summaries, findings, and recommendations to internal and external stakeholders.
- Provide other ad hoc support as required
Profile / Requirements :What profile are we looking for this position:
Must-have skills :
- A minimum of five years of relevant experience in information technology field, including triage of alerts and supporting security incidents
- Proven experience on administering a SIEM platform, preferably either Splunk or Microsoft Sentinel SIEM
- Proven experience with the usual toolbox available in a SOC (e.g., SIEMs, EDRs) and being able to autonomously perform technical analysis of security threats and collaborate with
Incident Response team
- Deep knowledge of Microsoft Security Tools (e.g. M365, Cloud App Security, Azure, Defender for Endpoints, Azure Security, Azure Sentinel and XDR
- Deep Knowledge of Cloud technologies (e.g. Azure, AWS and GCP)
- Deep knowledge of SIEM tools like Splunk, QRadar, ArcSight, MS Sentinel, ELK Stack
- Knowledge of at least one EDR solution (MS Defender for Endpoint, CrowdStrike)
- Knowledge of email security, network monitoring, and incident response
- Knowledge of Linux/Mac/Windows
- Expert knowledge of English, both written and spoken, is require
Nice to have :
- Experience in building SIEM architectures from initial design to implementation, including designing data ingestion pipelines for diverse log sources across cloud and on-prem
environments
- Proven knowledge of monitoring AWS environment (Iaas, Saas, Paas)
- Knowledge of at least one general-purpose or shell scripting language (e.g. Ruby, Bash, PowerShell, Python, etc.)