Назад
Company hidden
6 дней назад

Detection Engineer (Cybersecurity)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Detection Engineer (Splunk/SIEM): Building and maintaining production-ready cyber threat detections across SIEM, EDR, and enterprise security platforms with an accent on MITRE ATT&CK coverage, telemetry validation, and detection fidelity. Focus on translating red team findings and threat intelligence into actionable rules, reducing false positives, and developing investigation guidance for CSIRT and managed security teams.

Location: Not specified

Company

hirify.global is a global management consulting firm delivering business strategy, technology, design, and digital transformation services.

What you will do

  • Develop and maintain production detection rules across Splunk, EDR, SIEM, and other enterprise security platforms.
  • Translate red team exercises, penetration testing findings, threat intelligence, and operational feedback into actionable detections.
  • Validate detection accuracy against enterprise telemetry and continuously tune content to reduce false positives.
  • Identify MITRE ATT&CK coverage gaps and build detections for evolving adversary techniques.
  • Develop investigation guidance and runbooks for CSIRT and the managed security provider.
  • Partner with Security Engineering, CSIRT, Offensive Security, and Security Operations to improve detection coverage and telemetry quality.

Requirements

  • Experience developing and maintaining production detection rules across enterprise security platforms.
  • Strong knowledge of MITRE ATT&CK and adversary techniques.
  • Advanced proficiency with Splunk SPL or similar security query languages.
  • Understanding of offensive security techniques and experience with purple teaming, atomic testing, or similar validation methods.
  • Strong analytical skills and the ability to make sound technical decisions with incomplete or evolving information.
  • Experience collaborating with Security Operations, Incident Response, Engineering, and other technical teams.

Culture & Benefits

  • Work within BCG's global Security Operations and Cybersecurity organization.
  • Collaborate with internal cybersecurity teams and a managed security provider.
  • Contribute to a threat-led, evidence-based, and continuously validated detection program.
  • BCG is an Equal Opportunity Employer and an E-Verify Employer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →