Detection Engineer
Tasks
- Collaborate with SOC and NOSC analysts to tune alerts
- Coordinate telemetry ingestion normalization and field mappings
- Create detection dashboards and alerting content
- Develop correlation rules signatures behavioral analytics
- Develop detection logic for SIEM
- Document detection logic metadata versioned content change history
- Map detections to MITRE ATT&CK
- Review telemetry quality and coverage gaps
- Test detection rules in lab and datasets
- Translate threat intelligence into detection use cases
- Tune detections to reduce false positives
- Update runbooks for detection tuning and triage
- Validate detection operational readiness
Perks/Benefits
- N/A
Skills/Tech-stack
Analytic Queries | Automated testing | Behavioral analytics | Correlation rules | DCI | Data Ingestion | Data Normalization | Detection Performance Metrics | Detection and Response | Detection engineering | EDR | Endpoint Detection and Response | Endpoint detection | False Positive Tuning | Field mapping | IDS | IPS | KQL | MTTD | Mitre Attack | OT | OT Telemetry | Performance Metrics | Precisión | Recall | Runbooks | SIEM | SOAR | SOC Analytics | SPL | Security analytics | Sigma | Signatures | Telemetry Quality | Threat Intelligence | Vulnerability data
Education
Related jobs
-
Splunk Architect Lead USD 131K-216KBackup | Capacity Planning | Case management | Case management tools | Change ManagementSenior-level Full TimePortland, OR, United States2h ago
-
Senior Splunk Engineer USD 146K-219KAccess Control | Alerting | Dashboards | Data Ingestion | Data ModelSenior-level Full TimePortland, OR, United States2h ago
-
SIEM Infrastructure and Detection Engineer USD 120K-152KAlert Tuning | Ansible | Bash | Carbon Black | ChefClearance support | Healthcare benefits | Hybrid work | Paid time offMid-level Full TimePortland, OR, United States2h ago
-
Security Engineer USD 125K-178KAccess Management | Automation | CIS Controls | Cloud Security | Configuration ManagementSenior-level Full TimePortland, OR, United States2h ago
-
Threat Intelligence Analyst USD 112K-145KCyber Threat | Cyber threat analysis | Incident Response | Indicator of Compromise | Malware analysisMid-level Full TimePortland, OR, United States2h ago
-
SOC Threat Hunter USD 100K-141KCloud logging | Detection engineering | EDR | Endpoint telemetry | Event CorrelationMid-level Full TimePortland, OR, United States2h ago
-
AlgoSec Resident Engineer, Americas USD 120KAWS | Ansible | Application Connectivity | Azure | Change ManagementCollaborative culture | Home office arrangement | Travel opportunitiesSenior-level Full TimeUnited states, New Jersey, US5h ago
-
Data Synthesis | Deep learning | Language Models | Language Processing | Large Language ModelsEntry-level InternshipSan Jose, California, United States6h ago
-
Senior Cyber Security Engineer USD 128K-214KAccess Control | Centralized Configuration | Centralized Configuration Management | Certification and accreditation | Change ManagementSenior-level Full TimeUSA-VA-Chantilly6h ago
-
Senior Cyber Security Engineer USD 128K-214KAccess Control | Certification and accreditation | Change Management | DoD Security | DoD Security PolicySenior-level Full TimeUSA-VA-Chantilly6h ago
-
Senior Cyber Security Engineer USD 128K-214KAccess Control | Centralized Configuration | Centralized Configuration Management | Certification and accreditation | Configuration ManagementSenior-level Full TimeUSA-VA-Chantilly6h ago
-
Principal Cyber Systems Engineer USD 128K-214K800-53 | Access Control | Application Firewall | Cyber Defense | CybersecuritySenior-level Full TimeUSA-VA-Chantilly6h ago
-
Senior Analyst, Cyber Threat Intelligence Fusion USD 85K-150KAutomation | Cyber Kill Chain | Cyber Threat | Cyber Threat Intelligence | Dark Web401k matching | Employee assistance program | Employee discounts | Paid Holidays | Paid time offSenior-level Full TimeCharlotte, NC, 500 Woodward Avenue, MI, … R6h ago
-
Cybersecurity Okta Engineer USD 125K-153KAccess Management | Active Directory | Authentication | Authorization | Azure Active Directory401k | Education assistance | Onsite 2 days per week | Paid time off | TeleworkMid-level Full TimeQuantico, VA, 22134, US10h ago
-
Vice President, Information Security USD 83K-200KAPI Integration | Advanced Analytics | Ansible | Artifactory | AutomationExecutive-level Full TimeNew York, NY, United States16h ago
-
Alert triage | Antivirus | DNS | Data Loss Prevention | Data loss401k matching | Flexible time off | Higher education/training reimbursement | Hybrid work | Medical Dental Vision and Life Insurance coverageMid-level Full TimeWashington D.C., DC 20530, USA19h ago
-
DevSecOps Mission Systems Software Engineer USD 69K-158KAWS | Angular | Ansible | Automated testing | AzureDependent care | Hybrid work options | Paid leave | Professional development | Remote work optionsMid-level Full TimeUSA, NY, Rome (99 Otis St), …19h ago
-
Alarm Monitoring | Crisis Communications | Emergency response | Event Monitoring | Google WorkspaceSenior-level Full TimeRiverwoods, IL, United States19h ago
-
Senior Detection and Response Engineer USD 243K-295KAlert triage | Cloud Security | Container Security | Data Pipelines | Detection engineeringEquity compensation | Health and wellness benefits | Onsite/Hybrid scheduleSenior-level Full TimeSan Mateo, CA, United States R20h ago
-
Security Services Specialist USD 110K-160K24 7 monitoring | AI Security | AI security automation | Access Management | CISFull-time employment | Remote/hybrid workSenior-level Full TimeRemote (United States) R21h ago
-
Sr. Security Engineer 1 (Customer Trust) USD 145K-193K800-53 | AWS | CASB | CCSP | CI/CD401k match | Dental insurance | Flexible time off | Health insurance | Life insuranceSenior-level Full TimeBellevue, WA, USA R21h ago
-
Security Services Specialist USD 110K-160K24x7 monitoring | API Security | Application Security | CIS | CSPMSenior-level Full TimeChicago, IL R21h ago
-
ACAS | Adobe Acrobat | Adobe Experience | Adobe Experience Manager | Cybersecurity401k match | Dental insurance | FSA | HSA | Health insuranceMid-level Full TimeFt. Meade, MD22h ago
-
Mid-level Full TimeSan Diego, CA1d ago
-
Cybersecurity Tools Administrator USD 78K-160KCompliance | Data Rights Management | Data rights | Incident Response | Network SegmentationCareer growth | Certification support | Hands-on experience | Industry trainingSenior-level Full TimeArlington, VA1d ago