About this role
⭐️ CoreStar is a dynamic technology company supporting partners in heavy-load industries with high-performance solutions. Our expert teams bring a startup-driven mindset, focusing on innovation, collaboration, and efficiency in every project. At CoreStar, you’ll have the opportunity to grow your skills, tackle exciting challenges, and directly contribute to impactful products.
⭐️ About the Role
We are seeking an experienced L2 SOC Engineer to strengthen our Security Operations Center. This role goes beyond day-to-day alert triage, for you will be a technical backbone of the SOC, responsible for onboarding and tuning log sources into SIEM , designing and improving SOC detection and response processes, and leading incident response for escalated security events. You'll work closely with IT/infrastructure, Security teams, and NOC to ensure the SOC has the visibility and processes it needs to detect and respond to threats effectively.
📌 Key Responsibilities:
Log Source Onboarding & Data Engineering
- Own the end-to-end onboarding of new log sources into SIEM, including parsing, field extraction, normalisation, and enrichment
- Design and maintain log pipelines, parsing rules, and data mappings to ensure high-quality, actionable telemetry
- Build and maintain SIEM dashboards, alerts, and detection rules (e.g., SIEM Alerts, TCO optimisation, Data Flow rules)
- Continuously assess log coverage gaps across the environment (endpoint, network, cloud, identity, application) and drive onboarding roadmaps
- Optimise log volume, retention, and cost management within SIEM (TCO tiers, quota management)
- Validate data integrity and troubleshoot ingestion issues, parsing failures, or delayed telemetry
SOC Process Design & Improvement
- Design, document, and continuously improve SOC operating procedures, escalation matrices, and playbooks
- Develop and maintain detection use cases and correlation logic aligned to MITRE ATT&CK
- Define and track SOC KPIs/metrics (MTTD, MTTR, alert-to-incident ratio, false positive rates)
- Build standard operating procedures (SOPs) for L1 analysts and ensure consistent triage quality
- Support shift handover processes, escalation workflows, and quality assurance reviews of L1 work
Incident Response
- Act as the primary escalation point for incidents
- Lead investigation, containment, eradication, and recovery activities for security incidents
- Perform log correlation, timeline reconstruction, and root cause analysis using SIEM and supporting tools
- Coordinate with IT, DevOps, NOC, and business stakeholders during active incidents
- Author detailed incident reports, post-incident reviews (lessons learned), and drive remediation tracking
- Contribute to and maintain the organisation's Incident Response Plan (IRP)
📌 Required Qualifications
- 3-5+ years of experience in a SOC/ security operations role, with demonstrated progression to L2 or equivalent
- Strong experience with AI usage for SOC automation and detection.
- Hands on expertise with SIEM (such as Splunk, Sentinel, QRadar, Elastic, Datadog) — SIEM experience strongly preferred.
- Proven experience onboarding diverse log sources (firewalls, EDR, cloud platforms, identity providers, network devices, applications) into a SIEM/observability platform
- Solid understanding of incident response frameworks (e.g., NIST 800-61, SANS IR) and hands-on IR experience
- Strong knowledge of MITRE ATT&CK, common attack techniques, and detection engineering concepts
- Experience writing/tuning detection rules, correlation logic, and reducing false positives
- Familiarity with cloud environments (AWS/Azure/GCP) and cloud-native logging
- Scripting/query skills (e.g., DataPrime/Lucene query syntax in SIEM, Python, or similar) for automation and analysis
- Excellent documentation skills to design clear SOC processes, playbooks, and incident reports
- Strong communication skills; comfortable presenting findings to technical and non-technical stakeholders
📌 Benefits:
🏝 24 working days of paid annual leave
🤝 6 days of paid sick leave
🖊 Official employment
📄 Medical insurance
☕️ Coffee zone with fruit & snacks available in the office
🥗 Corporate Lunch provided by the company
💪 Gym and sports classes
🙌 Healthy and friendly work atmosphere
📚 Greek and English language classes (partially covered)
Join us and be one of the Core Stars! ⭐
