Назад
Company hidden
13 часов назад

SOC Detection Engineer – Senior (Cybersecurity)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
SOC Detection Engineer – Senior (Cybersecurity): Building and improving security detections across Windows, Linux, and Kubernetes environments with an accent on Splunk detection content, telemetry quality, and MITRE ATT&CK coverage. Focus on developing complex SPL queries, automating detection testing, reducing false positives, and supporting incident investigations, threat hunting, and attack emulation.

Location: Worldwide

Company

hirify.global develops technology for the iGaming industry and operates a Security Operations team focused on protecting its platforms and infrastructure.

What you will do

  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or another enterprise SIEM.
  • Translate incident investigations, threat hunting, attack research, purple team exercises, and attack emulation into effective detections.
  • Analyze false positives, false negatives, detection gaps, and telemetry quality while improving MITRE ATT&CK coverage.
  • Build and optimize SPL queries, dashboards, reports, risk-based detections, monitoring, and health checks.
  • Define logging, parsing, normalization, enrichment, and data-quality requirements across Windows, Linux, Kubernetes, and container environments.
  • Contribute to automated detection testing, synthetic events, telemetry replay, CI/CD workflows, and cross-functional security investigations.

Requirements

  • Strong hands-on experience in SOC, detection engineering, threat hunting, incident response, or a related field.
  • Deep understanding of MITRE ATT&CK, attack techniques, and detection methodologies.
  • Strong proficiency in Splunk SPL or another enterprise SIEM, including complex queries, correlations, dashboards, and reports.
  • Experience tuning detections, managing exceptions and allowlists, and defining logging and telemetry requirements.
  • Proficiency in Python, PowerShell, or Bash, plus experience with Git, code reviews, APIs, and basic CI/CD practices.
  • Understanding of Windows and Linux security monitoring and the ability to independently investigate complex problems.

Nice to have

  • Experience with Splunk Enterprise Security, CIM, data models, macros, lookups, Sysmon, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.
  • Experience with YARA, CALDERA, Shuffle, security automation, attack emulation, or automated detection validation frameworks.
  • Experience with Terraform, Ansible, or other infrastructure-as-code tools.
  • Participation in security research, conferences, or the broader security community.

Culture & Benefits

  • Private health insurance and a comprehensive mental health program.
  • Sports benefits, paid time off, and maternity leave support.
  • Free online English lessons and local language courses.
  • Upskilling opportunities, internal workshops, professional conferences, and corporate events.
  • Referral program rewards.

Hiring process

  • Hiring process information is provided through the official hirify.global careers channel.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →