Terminology Index
Glossary
1801 terms
Showing 1473-1504 of 1801 terms
Security Engineering
The discipline of building, deploying, and operating the security systems a SOC relies on, EDR, SIEM, identity, and detection infrastructure, so blue-team operations rest on capable, well-run platforms.
Security engineering builds the platforms blue teams depend on: deploying and tuning EDR, running the SIEM and its data pipelines, integrating identity and authentication systems, and engineering the detection and response infrastructure itself. It sits adjacent to analyst work, providing the capabilities analysts use rather than performing the analysis. As a blue-team-operations specialty, security engineering is what turns a paper SOC strategy into a working operational stack, and is a common path beyond the analyst role.
Introduced in: Blue Team Operations
Examples
- Engineering the SIEM data pipeline so detections have the right data.
- Deploying and tuning EDR across the environment.
- Building the detection-engineering infrastructure analysts work on.
No related terms linked yet.
