Назад
Company hidden
6 дней назад

Senior Security Engineer (Detection & Incident Response)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
CR
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Detection & Incident Response) (Cybersecurity): Building and refining security detections, incident response workflows, threat hunts, and automation for a 24/7 global security operations environment with an accent on Splunk, cloud and container monitoring, threat intelligence, and AI-assisted workflows. Focus on investigating complex incidents, improving signal quality, developing detection-as-code, and automating containment across endpoint, identity, SaaS, network, and cloud telemetry.

Location: Prague, Czech Republic; primarily in-office work from the Prague office is required

Company

hirify.global is a public data platform company serving hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem.

What you will do

  • Design, implement, test, and maintain Splunk detections and detection-as-code content using YAML/JSON, Sigma, and YARA-L.
  • Investigate and respond to security incidents across triage, scoping, containment, eradication, recovery, and post-incident reviews.
  • Conduct hypothesis-driven threat hunts using MITRE ATT&CK, the Diamond Model, kill chains, threat intelligence, behavioral baselines, and anomaly detection.
  • Improve detection quality by tuning logic, increasing true-positive rates, reducing alert fatigue, and mapping coverage to attacker techniques.
  • Build Python scripts, API integrations, enrichment workflows, and SOAR automation for faster investigation and containment.
  • Monitor cloud and container environments across AWS, GCP, and Azure, and develop AI-assisted investigation and triage workflows with appropriate guardrails.

Requirements

  • 6+ years of experience in cybersecurity, incident response, detection engineering, security operations, or a related discipline.
  • 3+ years of hands-on experience with threat hunting, complex incident investigations, or detection engineering in a SOC or SIEM environment.
  • Deep hands-on experience with Splunk, including searches, dashboards, alerts, correlation searches, deployment servers, and forwarders.
  • Strong knowledge of incident response, networking, operating systems, cloud environments, security architecture, threat intelligence, MITRE ATT&CK, the Diamond Model, kill chains, and TTPs.
  • Experience developing Python scripts for security tooling, data processing, API integrations, and automation.
  • Excellent written and verbal English communication skills and a bachelor's degree in computer science, information security, engineering, or equivalent practical experience.

Nice to have

  • Detection-as-code experience with Sigma, ECMA/JSON, Git-backed repositories, unit testing, and Splunk Security Content.
  • Experience with Tines, XSOAR, Splunk SOAR, or equivalent SOAR platforms.
  • Cloud security operations across AWS, GCP, or Azure, including CloudTrail, GuardDuty, and cloud audit logs.
  • Container and Kubernetes security experience, including Falco, runtime monitoring, image scanning, vulnerability management, or software supply chain security.
  • Experience with AI-assisted security workflows, threat intelligence operations, infrastructure as code, follow-the-sun operations, or attack surface management.

Culture & Benefits

  • Work in a global security operations environment focused on operational excellence, collaboration, knowledge sharing, and continuous improvement.
  • Innovation-oriented environment that values critical thinking and challenging technical work.
  • Flexible time off, wellness resources, and company-sponsored team events.
  • Growth and development support with an inclusive workplace and employee resource groups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →