13 часов назад
SOC Detection Engineer – Senior (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Detection Engineer – Senior (Cybersecurity): Building and improving security detections across Windows, Linux, and Kubernetes environments with an accent on Splunk detection content, telemetry quality, and MITRE ATT&CK coverage. Focus on developing complex SPL queries, automating detection testing, reducing false positives, and supporting incident investigations, threat hunting, and attack emulation.
Location: Worldwide
Company
develops technology for the iGaming industry and operates a Security Operations team focused on protecting its platforms and infrastructure.
What you will do
- Develop, test, deploy, and maintain detection and correlation rules in Splunk or another enterprise SIEM.
- Translate incident investigations, threat hunting, attack research, purple team exercises, and attack emulation into effective detections.
- Analyze false positives, false negatives, detection gaps, and telemetry quality while improving MITRE ATT&CK coverage.
- Build and optimize SPL queries, dashboards, reports, risk-based detections, monitoring, and health checks.
- Define logging, parsing, normalization, enrichment, and data-quality requirements across Windows, Linux, Kubernetes, and container environments.
- Contribute to automated detection testing, synthetic events, telemetry replay, CI/CD workflows, and cross-functional security investigations.
Requirements
- Strong hands-on experience in SOC, detection engineering, threat hunting, incident response, or a related field.
- Deep understanding of MITRE ATT&CK, attack techniques, and detection methodologies.
- Strong proficiency in Splunk SPL or another enterprise SIEM, including complex queries, correlations, dashboards, and reports.
- Experience tuning detections, managing exceptions and allowlists, and defining logging and telemetry requirements.
- Proficiency in Python, PowerShell, or Bash, plus experience with Git, code reviews, APIs, and basic CI/CD practices.
- Understanding of Windows and Linux security monitoring and the ability to independently investigate complex problems.
Nice to have
- Experience with Splunk Enterprise Security, CIM, data models, macros, lookups, Sysmon, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.
- Experience with YARA, CALDERA, Shuffle, security automation, attack emulation, or automated detection validation frameworks.
- Experience with Terraform, Ansible, or other infrastructure-as-code tools.
- Participation in security research, conferences, or the broader security community.
Culture & Benefits
- Private health insurance and a comprehensive mental health program.
- Sports benefits, paid time off, and maternity leave support.
- Free online English lessons and local language courses.
- Upskilling opportunities, internal workshops, professional conferences, and corporate events.
- Referral program rewards.
Hiring process
- Hiring process information is provided through the official careers channel.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Senior Detection and Response Engineer (Fintech)
170 000 - 225 000$
3 дня назад
Senior Cyber Defense Engineer (AI)
121 300 - 192 692$
7 дней назад
SecOps Specialist (SIEM/SOAR)
7 дней назад
Senior Security Engineer (Detection & Response)
167 500 - 235 000$
5 дней назад
Senior Detection Engineer (Cybersecurity)
3 дня назад