5 дней назад
Cyber Use Case Developer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Use Case Developer (Cybersecurity): Designing, developing, testing, and improving security monitoring use cases across network, cloud, endpoint, identity, and hybrid environments with an accent on network telemetry, threat detection, and MITRE ATT&CK coverage. Focus on translating adversary behaviours into detection logic, tuning alerts to reduce false positives, and validating detection capabilities through threat hunting, incident response, and attack simulation.
Location: Ireland
Company
provides financial security and health-related services to clients worldwide.
What you will do
- Design, develop, test, deploy, document, and maintain cybersecurity detection use cases across SIEM, EDR, XDR, cloud, identity, endpoint, and network data sources.
- Translate adversary tactics, techniques, and procedures into detection logic mapped to the MITRE ATT&CK framework.
- Analyze network telemetry, logs, alerts, packet metadata, flow data, and incident information to identify suspicious activity and detection gaps.
- Create detections for command-and-control activity, lateral movement, beaconing, port scanning, suspicious remote access, anomalous DNS activity, data exfiltration, and policy violations.
- Collaborate with Security Operations, Threat Hunting, Cyber Threat Intelligence, Incident Response, Network Security, infrastructure, and engineering teams.
- Measure detection performance, conduct false-positive analysis, tune alert content, and support purple-team, attack-simulation, tabletop, and control-validation activities.
Requirements
- Post-secondary education in cybersecurity, information technology, computer science, information systems, or a related field, or equivalent practical experience.
- Experience in security operations, detection engineering, threat hunting, incident response, cyber threat intelligence, network operations, or a related cybersecurity function.
- Hands-on experience with firewalls, proxies, DNS, DHCP, VPN platforms, IDS/IPS, NAC, packet capture, or similar network security technologies.
- Experience writing detection logic or search queries using SPL, KQL, SQL, Sigma, YARA, Python, PowerShell, or similar languages.
- Strong knowledge of TCP/IP, routing, switching, firewalls, VPNs, proxies, DNS, HTTP/S, TLS, email gateways, network segmentation, secure network architecture, attacker behaviours, and malware techniques.
- Ability to analyze large volumes of security data, identify actionable patterns, and communicate findings through clear documentation and stakeholder collaboration.
Culture & Benefits
- Collaborative environment with experienced cybersecurity, technology, and infrastructure professionals.
- Work focused on improving early threat identification, alert fidelity, and incident response capabilities.
- Opportunities to contribute to security monitoring improvements and make a meaningful impact on client protection.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →