Detection Engineer
Tasks
- Collaborate with SOC and NOSC analysts to tune alerts
- Coordinate telemetry ingestion normalization and field mappings
- Create detection dashboards and alerting content
- Develop correlation rules signatures behavioral analytics
- Develop detection logic for SIEM
- Document detection logic metadata versioned content change history
- Map detections to MITRE ATT&CK
- Review telemetry quality and coverage gaps
- Test detection rules in lab and datasets
- Translate threat intelligence into detection use cases
- Tune detections to reduce false positives
- Update runbooks for detection tuning and triage
- Validate detection operational readiness
Perks/Benefits
- N/A
Skills/Tech-stack
Analytic Queries | Automated testing | Behavioral analytics | Correlation rules | DCI | Data Ingestion | Data Normalization | Detection Performance Metrics | Detection and Response | Detection engineering | EDR | Endpoint Detection and Response | Endpoint detection | False Positive Tuning | Field mapping | IDS | IPS | KQL | MTTD | Mitre Attack | OT | OT Telemetry | Performance Metrics | Precisión | Recall | Runbooks | SIEM | SOAR | SOC Analytics | SPL | Security analytics | Sigma | Signatures | Telemetry Quality | Threat Intelligence | Vulnerability data
Education
Related jobs
-
GRC (Governance Risk and Compliance) Analyst USD 106K-130K800-171 | AWS | Active Directory | Antivirus | AzureCareer advancement opportunities | Extensive training | Professional education | Travel opportunitiesMid-level Full TimeDENVER, CO, US, 802376h ago
-
Information Security Analyst - Temporary USD 80K-95KDetection engineering | Endpoint detection | IDS | IPS | Incident Response401k match | Employee assistance program | Employee resource groups | HSA & FSA options | Hardship support fundMid-level Full Time TemporaryTempe, AZ, United States R13h ago
-
Security Engineer USD 110K-120KCloudFormation | CrowdStrike | Dashboarding | EDR | Go401k match | Annual professional development budget | Charitable donation match | Commuter benefits | Dental insuranceMid-level Full TimeRemote - United States R17h ago
-
Entry-level Full TimeKansas City, KS, United States18h ago
-
Senior Threat Detection Engineer USD 121K-190KAPIs | AWS | AWS GuardDuty | Azure | Azure DefenderCross-functional collaboration | Hybrid work | Training and developmentSenior-level Full TimeRoseland, NJ, United States19h ago
-
Lead Cloud Security Engineer - Kubernetes USD 144K-196KAPI | AWS | Active Directory | Ansible | AutomationSenior-level Full TimeRoseland, NJ, United States19h ago
-
AWS | Alert triage | Azure | Cloud Security | DockerBuddy program | Hybrid workplace | Mentor program | On-call rotation | Paid time offSenior-level Full TimeNew York, New York, USA19h ago
-
Senior Security Engineer - Northeast USD 170K-230KAccount Management | Attack Intelligence | Best practices | Blue Team | CASBBehavioral wellness services | Employee recognition program | Generous time off | Health insurance | Life insuranceSenior-level Full TimeUS - New Jersey, US - …19h ago
-
Security Engineer USD 125K-150KCapacity Planning | Data Enrichment | Data Ingestion | Data Normalization | Detection rule tuning401k | Certification sponsorship | Continuous learning | Medical, dental, and vision insurance | Paid Company HolidaysMid-level Full TimeUnited States20h ago
-
Senior Incident Response Engineer USD 108K-161KAWS | Cloud platform | Databricks | Detection and Response | Digital forensicsCareer development | Financial benefits | Health insuranceSenior-level Full TimeManhattan, New York, United States21h ago
-
Threat Hunt Lead USD 116K-126KAdversary tracking | Behavioral analytics | Data Analysis | Detection and Response | Detection engineering401k match | Dental insurance | Disability insurance | Employee assistance program | Flexible spending accountSenior-level Full TimeMississippi, John C. Stennis Space Center, …23h ago
-
SADOM Lead USD 120K-132KAnsible | Automation | Chef | Configuration Management | Database Administration401k match | Dental insurance | Disability insurance | Employee assistance program | Flexible spending accountSenior-level Full TimeMississippi, John C. Stennis Space Center, …23h ago
-
Cyber Threat Lead USD 125K-210KCloud Security | Data Science | Detection and Response | Endpoint Detection and Response | Endpoint detectionSenior-level Full TimeUSA-VA-Chantilly, USA-AZ-Chandler23h ago
-
Security Operations Center Analyst USD 91K-117KAlert triage | Cyber Threat | Cyber Threat Detection | Detection and Response | Email SecurityCareer development opportunities | Remote work up to 2 days per weekEntry-level Full TimeNew York, NY, United States1d ago
-
Cause analysis | EDR | Governance | IDSIPS | ISO 27001401k program | Car discounts | Cruise discounts | Dental benefits | Employee assistance programSenior-level Full TimeFort Worth, TX, US1d ago
-
Digital Forensics Analyst USD 104K-166KCellebrite | Chain of Custody | Cloud Forensics | Computer forensics | Computer forensics toolsSenior-level Full TimeHerndon, VA, United States1d ago
-
DevSecOps Engineer Senior USD 115K-191KAnsible | Automated testing | Automation | CI/CD | Configuration ManagementSenior-level Full TimeOrlando, FL, United States1d ago
-
SITEC - Endpoint Security Engineer - MacDill AFB USD 104K-166KAPI Integration | Cloud Security | Endpoint Security | IMAC | Incident ResponseSenior-level Full TimeMacDill AFB, FL, United States1d ago
-
Splunk Engineer USD 140K-180KAWS CloudTrail | AWS CloudWatch | Alert configuration | Alerting | Authentication integrationEmployee-owned companySenior-level Full TimeWashington, DC, United States1d ago
-
Endpoint Engineer USD 66K-106KATO Evidence | Asset Management | Compliance dashboards | Configuration Drift | Configuration ManagementSenior-level Full TimeHerndon, VA, United States1d ago
-
Senior-level Full TimeHerndon, VA, United States1d ago
-
Sr. Full Stack Engineer USD 103K-155KAgile | Amazon Web Services | Automated testing | Automation | CI/CD401k retirement plan | Dental insurance | Disability insurance | Employee discounts | Employee stock purchase planSenior-level Full TimeMinneapolis, MN, United States1d ago
-
Sr. Intelligence Analyst - China Mission (Remote) USD 85K-120KAnalytic techniques | Analytic tradecraft | Confidence Level Assessment | Cyber Threat | Cyber threat analysisConference participation opportunities | Employee resource groups | Paid adoption leave | Paid parental leave | Professional development opportunitiesSenior-level Full TimeUSA TX Remote, United States R1d ago
-
Cybersecurity Engineer II USD 78K-101KBash | C# | C++ | Device security | Fuzz testing401k match | Dental insurance | Disability insurance | Health insurance | Long-term disabilityMid-level Full TimeMentor, OH, US, 440601d ago
-
Mid-level Full TimeWarren, MI, US1d ago