Detection Analyst (Elastic)
Charleston, SC, United States
USD 130K-140K (estimate) Mid-level Full Time
Tasks
- Analyze threat intelligence to refine detections
- Assess detection tool efficacy through program reviews
- Coordinate detection strategy with reporting agencies and subscriber sites
- Correlate logs using Elastic Security
- Create and optimize IDS IPS signatures
- Develop detection rules and logic in Elastic Security
- Document detection creation and implementation processes
- Integrate detections into monitoring and incident response workflows
- Maintain and update detections for evolving threats
- Validate and test detections to reduce false positives
Perks/Benefits
- N/A
Skills/Tech-stack
EQL | ESQL | Elastic Defend | Elastic Security | Elasticsearch | Elasticsearch Query | Elasticsearch Query Language | Event Query Language | IDS/IPS | Indicator management | KQL | Kibana Query Language | Log Correlation | MITRE ATT&CK | Query Language | Signature development | Threat Intelligence | Threat hunting
Education
Roles
Regions
Countries
States
Related jobs
-
Embedded Intelligence Analyst USD 130K-130KBrandwatch | Crisis management | Dark Web | Data Analysis | Deep Web401k match | Disability insurance | Employee assistance program | Employee discount program | Life insuranceMid-level Full TimeSan Jose, CA, United States R9h ago
-
Team Lead, Security Operations Center (SOC) - 2nd Shift USD 121K-152KCyber Security | Detection engineering | EDR | Evidence Based Investigation | Incident Response401(k) plan matching | Bereavement leave | Employee assistance program | Employee discount program | Health and wellbeing benefitsSenior-level Full TimeRemote - Nationwide, United States R11h ago
-
Case management | Corelight | CrowdStrike | Cyware CSAP | Detection SystemsHybrid work | On-call rotation | Telework optionMid-level ContractAustin, United States13h ago
-
Automated Enrichment Workflows | Automated enrichment | Correlation rules | Data Normalization | Detection engineeringHybrid work | Occasional after-hours supportMid-level ContractAustin, United States13h ago
-
Cloud Security | Cybersecurity | Data Architecture | Hybrid Data | Hybrid Data ArchitectureOnsite work 5 days per weekSenior-level Full TimeLas Vegas, Nevada, United States15h ago
-
Manager - AI SOC USD 134K-265KApplication Programming | Application Programming Interface | Automation | Automation and response | Case managementMid-level Full TimeChicago, Illinois, United States15h ago
-
Access Control | Access Control Lists | Alert analysis | Coverage Validation | Detection Coverage ValidationOnsite work | Travel opportunitiesMid-level Full TimeArlington/Rosslyn, Virginia, United States15h ago
-
AI Security Analyst | Camden Corporate Office USD 128K-237KAI/ML | Access Control | Application Firewall | Automation | AzureDisaster recovery exercise support | Off-hours support | Periodic travelSenior-level Full TimeHouston, TX, United States23h ago
-
Engineer IV, Cybersecurity USD 180K-205KAWS | Access Management | Artificial Intelligence | Azure | DevSecOps401k match | Dental insurance | Disability insurance | Life insurance | Medical insuranceSenior-level Full TimeMD - Gaither Rd., Rockville Corp …1d ago
-
Security Operations Center Analyst USD 99K-225KEvent analysis | IT Forensics | Incident Response | Incident investigation | Security incident24/7 shift work | Dependent care | Paid leave | Professional development | Remote or hybrid or onsite work flexibilityEntry-level Full TimeUSA, NC, Fort Bragg (2175 Reilly …1d ago
-
Sr Information Security Analyst (US) USD 79K-127KApplication Security | Automation | Cloud Security | Cloud apps | Defender XDRCareer development | Skill development | Training programsSenior-level Full TimeMt Laurel - Technology Center - …1d ago
-
AVP - Information Security - Americas USD 171K-256KAI Governance | AWS | Access Management | Anomaly Detection | Artificial IntelligenceExecutive-level Full TimeNorfolk, VA, United States1d ago
-
Intelligence Lead Analyst - OSINT Threat Hunting USD 117K-176KAnalyst’s Notebook | Bash | Dark Web | Dark web monitoring | Dynamic analysis401k | Dental insurance | Disability insurance | Health insurance | Life insuranceSenior-level Full TimeCharlotte, North Carolina, UNITED STATES; Tampa, …1d ago
-
Director, Security Operations & SOC Leader USD 168K-255K800-171 | Automated response | CISSP | CMMC | Content LifecycleSenior-level ContractLowell, United States; Lowell, MA, United …1d ago
-
Vice President, Senior SOC Analyst- Tuesday- Saturday USD 135K-224KAccess Management | Automation | CIS Controls | Cloud logging | CrowdStrikeFlexible benefits | Paid leave | Paid volunteer time | Wellbeing programsSenior-level Full TimePittsburgh, PA, United States1d ago
-
Cybersecurity Analyst USD 125K-150KApplication Security | Audit Logging | Automation | Blue Teaming | CI/CDMid-level Full TimeNew York1d ago
-
Senior Security Analyst I USD 140K-176KAdversary tactics | Anomaly Detection | Bash | Cloud infrastructure | ClusteringConference reimbursement | Education reimbursement | Employee assistance program | Employee stock purchase program | Flexible time offSenior-level Full TimeSeattle1d ago
-
Senior Security Analyst I USD 140K-176KAdversary tactics | Anomaly Detection | Bash | Clustering | DLPConference reimbursement | Employee assistance program | Flexible time off | LinkedIn Learning access | Local Employee MeetupsSenior-level Full TimeDenver R1d ago
-
Senior Security Analyst I USD 140K-176KBash | Cloud Security | DLP | Go | KubernetesEmployee assistance program | Flexible time off | LinkedIn Learning access | Remote work | Training and education reimbursementSenior-level Full TimeBoston R1d ago
-
Senior Security Analyst I USD 140K-176KAnomaly Detection | Bash | Cloud infrastructure | DFIR | DLPConference reimbursement | Employee assistance program | Flexible time off | LinkedIn Learning access | Local Employee MeetupsSenior-level Full TimeAustin R1d ago
-
Senior Security Analyst I USD 140K-176KAnomaly Detection | Bash | Cloud Security | Clustering | DLPConference reimbursement | Employee assistance program | Flexible time off | LinkedIn Learning access | Local Employee MeetupsSenior-level Full TimeSan Francisco R1d ago
-
Security Analyst USD 78K-97KCIS Controls | CrowdStrike Falcon | Cybersecurity Framework | Detection rules | Digital forensicsMid-level Full TimeTallassee, Alabama, United States; Duluth, Georgia, …1d ago
-
Principal Applied Threat Intelligence Analyst USD 142K-304KAnalytic techniques | Anomaly Detection | Artificial Intelligence | Attribution | Behavioral AnalysisSenior-level Full TimeRedmond, WA, US; Reston, VA, US1d ago
-
Senior Director, Cybersecurity Architecture USD 160K-225KAWS Security | Access Management | Application Security | Architecture governance | Azure SecuritySenior-level Full TimeCleveland, OH, United States R1d ago
-
Engineering Manager I - Threat Detection, Applied AI USD 192K-240KArtificial Intelligence | Automation | Detection engineering | Evaluation | Incident ResponseCareer development | Employee mentoring buddy program | Employee stock purchase plan | Fitness reimbursements | Hybrid workplaceMid-level Full TimeNew York, New York, USA1d ago