Назад
Company hidden
2 дня назад

Senior Security Engineer (Threat Intelligence & Detection)

142 000 - 220 500$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Threat Intelligence & Detection): Building high-fidelity detection rules, threat intelligence workflows, hunting programs, and security automation across endpoint, email, identity, network, and cloud telemetry with an accent on MITRE ATT&CK mapping, incident investigation, and enterprise SIEM/XDR operations. Focus on designing hypothesis-driven hunts, integrating SIEM and security platforms, automating IOC and detection workflows, and improving response to identity compromise, endpoint intrusion, and data exfiltration.

Location: Hybrid in Seattle, Washington; office attendance at the hirify.global corporate headquarters is required at least 4 days per week.

Salary: $142,000–$220,500 annual, with possible performance-based incentives or bonuses.

Company

hirify.global is a retail and e-commerce company offering customer merchandise and related services.

What you will do

  • Design, develop, test, deploy, tune, and retire high-fidelity detection rules in CrowdStrike NG-SIEM using LogScale/CQL.
  • Collect and operationalize threat intelligence, producing threat actor profiles, TTP summaries, and IOC packages.
  • Execute hypothesis-driven threat hunts across endpoint, email, identity, network, and cloud telemetry.
  • Support complex incident investigations involving identity compromise, endpoint intrusion, lateral movement, and data exfiltration.
  • Build integrations and automation across SIEM, EDR, email security, SOAR, and threat intelligence platforms using Python and PowerShell.
  • Mentor team members and partner with SOC, IAM, platform engineering, email security, and cloud teams.

Requirements

  • 4+ years of professional experience in detection engineering, threat intelligence, SOC/incident response, threat hunting, or security automation.
  • Experience writing detection logic in an enterprise SIEM or XDR platform; CrowdStrike NG-SIEM, LogScale, or CQL experience is strongly preferred.
  • Working knowledge of MITRE ATT&CK techniques and sub-techniques, including mapping adversary behavior to telemetry and detection logic.
  • Hands-on experience with EDR analysis, behavioral anomaly detection, threat hunting, and post-exploitation investigations.
  • Proficiency in Python and/or PowerShell for automation, log parsing, or investigative tooling.
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.

Nice to have

  • Experience with identity attacks, enterprise email security, SOAR, threat intelligence platforms, STIX/TAXII, detection-as-code, Git, and CI/CD.
  • Experience with Azure or AWS security telemetry and cloud-native attack detection.
  • Use of AI tools for detection development, security operations, or threat research.
  • GIAC certifications such as GCIA, GCIH, GCTI, or GDAT.

Culture & Benefits

  • Medical, vision, dental, life, and disability insurance options.
  • Retirement benefits including a 401(k).
  • Paid time away, PTO accruals, and holidays.
  • Merchandise discounts and employee assistance resources.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →