SIEM vs. SOAR vs. EDR

How to tell them apart on a resume

SIEM (collect and alert)

Splunk, Microsoft Sentinel, QRadar, ArcSight, Elastic, writing detection rules or queries, log sources — the SOC's main screen.

SOAR (automate response)

Splunk SOAR (Phantom), Cortex XSOAR, Sentinel playbooks, Python scripting, automated triage — reducing analysts' manual work.

EDR / XDR (endpoints)

CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black, isolating machines, threat hunting on devices.

The question that settles it

“Did you mostly respond to alerts others had set up, or write the detection rules and automation yourself — and in which tool?”

Read the full definitions

Open the full tool for the other look-alike pairs, role profiles, and the JD decoder.