Security Operation Center L2 Engineer

CoreStarLimassol, LimassolOn-siteFull-timeMid level, 2–5 yearsListed 2 weeks ago

Apply now

About this role

⭐️  CoreStar  is a dynamic technology company supporting partners in heavy-load industries with high-performance solutions. Our expert teams bring a startup-driven mindset, focusing on innovation, collaboration, and efficiency in every project. At CoreStar, you’ll have the opportunity to grow your skills, tackle exciting challenges, and directly contribute to impactful products.

⭐️  About the Role

We are seeking an experienced L2 SOC Engineer to strengthen our Security Operations Center. This role goes beyond day-to-day alert triage, for you will be a technical backbone of the SOC, responsible for onboarding and tuning log sources into SIEM , designing and improving SOC detection and response processes, and leading incident response for escalated security events. You'll work closely with IT/infrastructure, Security teams, and NOC to ensure the SOC has the visibility and processes it needs to detect and respond to threats effectively.

📌 Key Responsibilities:

Log Source Onboarding & Data Engineering

- Own the end-to-end onboarding of new log sources into SIEM, including parsing, field extraction, normalisation, and enrichment

- Design and maintain log pipelines, parsing rules, and data mappings to ensure high-quality, actionable telemetry

- Build and maintain SIEM dashboards, alerts, and detection rules (e.g., SIEM Alerts, TCO optimisation, Data Flow rules)

- Continuously assess log coverage gaps across the environment (endpoint, network, cloud, identity, application) and drive onboarding roadmaps

- Optimise log volume, retention, and cost management within SIEM (TCO tiers, quota management)

- Validate data integrity and troubleshoot ingestion issues, parsing failures, or delayed telemetry

SOC Process Design & Improvement

- Design, document, and continuously improve SOC operating procedures, escalation matrices, and playbooks

- Develop and maintain detection use cases and correlation logic aligned to MITRE ATT&CK

- Define and track SOC KPIs/metrics (MTTD, MTTR, alert-to-incident ratio, false positive rates)

- Build standard operating procedures (SOPs) for L1 analysts and ensure consistent triage quality

- Support shift handover processes, escalation workflows, and quality assurance reviews of L1 work

Incident Response

- Act as the primary escalation point for incidents

- Lead investigation, containment, eradication, and recovery activities for security incidents

- Perform log correlation, timeline reconstruction, and root cause analysis using SIEM and supporting tools

- Coordinate with IT, DevOps, NOC, and business stakeholders during active incidents

- Author detailed incident reports, post-incident reviews (lessons learned), and drive remediation tracking

- Contribute to and maintain the organisation's Incident Response Plan (IRP)

📌 Required Qualifications

- 3-5+ years of experience in a SOC/ security operations role, with demonstrated progression to L2 or equivalent

- Strong experience with AI usage for SOC automation and detection.

- Hands on expertise with SIEM  (such as Splunk, Sentinel, QRadar, Elastic, Datadog) — SIEM experience strongly preferred.

- Proven experience onboarding diverse log sources (firewalls, EDR, cloud platforms, identity providers, network devices, applications) into a SIEM/observability platform

- Solid understanding of incident response frameworks (e.g., NIST 800-61, SANS IR) and hands-on IR experience

- Strong knowledge of MITRE ATT&CK, common attack techniques, and detection engineering concepts

- Experience writing/tuning detection rules, correlation logic, and reducing false positives

- Familiarity with cloud environments (AWS/Azure/GCP) and cloud-native logging

- Scripting/query skills (e.g., DataPrime/Lucene query syntax in SIEM, Python, or similar) for automation and analysis

- Excellent documentation skills to design clear SOC processes, playbooks, and incident reports

- Strong communication skills; comfortable presenting findings to technical and non-technical stakeholders

📌 Benefits:

🏝 24 working days of paid annual leave

🤝 6 days of paid sick leave

🖊 Official employment

📄 Medical insurance

☕️ Coffee zone with fruit & snacks available in the office

🥗 Corporate Lunch provided by the company

💪 Gym and sports classes

🙌 Healthy and friendly work atmosphere

📚 Greek and English language classes (partially covered)

Join us and be one of the Core Stars! ⭐