This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a Cyber Defence – SIEM Content Development Specialist to strengthen Vodafone’s global Cyber Security Operations Centre (CSOC) detection capability by designing, developing and optimising security detection content across SIEM and EDR/XDR platforms. This role focuses on understanding the evolving threat landscape, translating business and security requirements into actionable detection logic, and continuously improving threat detection and response outcomes across Vodafone.
Job Responsibility
Design, develop and fine-tune detection rules and use cases across existing and new SIEM platforms, with a strong focus on Elastic (ELK) and other leading SIEM technologies
Lead and contribute to security content engineering initiatives, applying secure software development lifecycle (SDLC) and agile practices
Analyse attacker behaviour, threat intelligence, MITRE ATT&CK techniques and adversary tooling to create indicator-based and behavioural detections
Support and, where required, lead threat response workflows and playbook creation, ensuring seamless integration with CSOC operations
Collaborate closely with log source owners, engineering teams and stakeholders to understand telemetry, risks and operational requirements, translating them into effective detection content
Deliver security reporting, advisories and post-incident analysis, converting lessons learnt into measurable improvements in detection and response
Maintain clear documentation, including detection logic, workflows and operational playbooks, to support consistent CSOC operations
Requirements
Experienced cyber security professional with a strong background in SOC operations, SIEM content development, threat hunting or security engineering
Skilled in SIEM technologies, with hands-on experience in Elastic/ELK and working knowledge of platforms such as ArcSight, Microsoft Sentinel, Splunk or Chronicle
Comfortable working with cloud and endpoint telemetry across environments such as AWS, GCP and Microsoft security tooling
Technically confident, with experience in programming or scripting (for example Python, SQL, JavaScript, PowerShell, KQL or ES|QL) and strong capability in regular expression development
Knowledgeable in security frameworks and threat models, including MITRE ATT&CK, cyber kill chain concepts and advanced persistent threat strategies
Analytical, collaborative and able to work independently, making informed decisions while building strong relationships across the security community