6 дней назад
Senior Security Engineer (Detection & Incident Response)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (Detection & Incident Response) (Cybersecurity): Building and refining security detections, incident response workflows, threat hunts, and automation for a 24/7 global security operations environment with an accent on Splunk, cloud and container monitoring, threat intelligence, and AI-assisted workflows. Focus on investigating complex incidents, improving signal quality, developing detection-as-code, and automating containment across endpoint, identity, SaaS, network, and cloud telemetry.
Location: Prague, Czech Republic; primarily in-office work from the Prague office is required
Company
is a public data platform company serving hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem.
What you will do
- Design, implement, test, and maintain Splunk detections and detection-as-code content using YAML/JSON, Sigma, and YARA-L.
- Investigate and respond to security incidents across triage, scoping, containment, eradication, recovery, and post-incident reviews.
- Conduct hypothesis-driven threat hunts using MITRE ATT&CK, the Diamond Model, kill chains, threat intelligence, behavioral baselines, and anomaly detection.
- Improve detection quality by tuning logic, increasing true-positive rates, reducing alert fatigue, and mapping coverage to attacker techniques.
- Build Python scripts, API integrations, enrichment workflows, and SOAR automation for faster investigation and containment.
- Monitor cloud and container environments across AWS, GCP, and Azure, and develop AI-assisted investigation and triage workflows with appropriate guardrails.
Requirements
- 6+ years of experience in cybersecurity, incident response, detection engineering, security operations, or a related discipline.
- 3+ years of hands-on experience with threat hunting, complex incident investigations, or detection engineering in a SOC or SIEM environment.
- Deep hands-on experience with Splunk, including searches, dashboards, alerts, correlation searches, deployment servers, and forwarders.
- Strong knowledge of incident response, networking, operating systems, cloud environments, security architecture, threat intelligence, MITRE ATT&CK, the Diamond Model, kill chains, and TTPs.
- Experience developing Python scripts for security tooling, data processing, API integrations, and automation.
- Excellent written and verbal English communication skills and a bachelor's degree in computer science, information security, engineering, or equivalent practical experience.
Nice to have
- Detection-as-code experience with Sigma, ECMA/JSON, Git-backed repositories, unit testing, and Splunk Security Content.
- Experience with Tines, XSOAR, Splunk SOAR, or equivalent SOAR platforms.
- Cloud security operations across AWS, GCP, or Azure, including CloudTrail, GuardDuty, and cloud audit logs.
- Container and Kubernetes security experience, including Falco, runtime monitoring, image scanning, vulnerability management, or software supply chain security.
- Experience with AI-assisted security workflows, threat intelligence operations, infrastructure as code, follow-the-sun operations, or attack surface management.
Culture & Benefits
- Work in a global security operations environment focused on operational excellence, collaboration, knowledge sharing, and continuous improvement.
- Innovation-oriented environment that values critical thinking and challenging technical work.
- Flexible time off, wellness resources, and company-sponsored team events.
- Growth and development support with an inclusive workplace and employee resource groups.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →