Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1473-1504 of 1801 terms

S
32

Security Engineering

The discipline of building, deploying, and operating the security systems a SOC relies on, EDR, SIEM, identity, and detection infrastructure, so blue-team operations rest on capable, well-run platforms.

Security engineering builds the platforms blue teams depend on: deploying and tuning EDR, running the SIEM and its data pipelines, integrating identity and authentication systems, and engineering the detection and response infrastructure itself. It sits adjacent to analyst work, providing the capabilities analysts use rather than performing the analysis. As a blue-team-operations specialty, security engineering is what turns a paper SOC strategy into a working operational stack, and is a common path beyond the analyst role.

Introduced in: Blue Team Operations

Examples

  • Engineering the SIEM data pipeline so detections have the right data.
  • Deploying and tuning EDR across the environment.
  • Building the detection-engineering infrastructure analysts work on.

No related terms linked yet.