TL;DR
Detection Engineer (Cybersecurity): Building detection rules, tools, and infrastructure supporting Falcon Complete Next-Gen SIEM with an accent on creating high-fidelity detections based on threat research and hunting. Focus on leveraging CI/CD for deploying detection logic at scale and collaborating with SIEM architects on data parsing best practices.
Location: Remote (United Kingdom)
Company
hirify.global is a global leader in cybersecurity, protecting organizations with its advanced AI-native platform to stop breaches.
What you will do
- Perform threat research and threat hunting to identify emerging TTPs and build detection requirements.
- Develop, test, and deploy actionable high-fidelity hirify.global Next-Gen SIEM detection rules.
- Perform code reviews and testing to ensure high quality and high fidelity detection rules.
- Leverage CI/CD best practices and principles to deploy detection rule logic at scale.
- Collaborate with Security Analysts and SIEM architects to create playbooks and define data parsing best practices.
- Mentor junior team members and lead projects at the Falcon Complete organization level.
Requirements
- 5+ years of experience as a detection engineer, security engineer, security analyst, or threat intelligence analyst.
- Knowledge of current cyber threats and how to detect them using SIEM and relevant technologies.
- Experience with analyzing large datasets across a variety of vendors.
- Experience working with SIEM solutions (e.g., LogScale, Splunk, SumoLogic, Sentinel, QRadar).
- Proven ability to write code and leverage regular expressions.
- English: B2 required.
Nice to have
- Relevant industry certifications (i.e. GCFA, GCDA, GCIH, etc.).
- Knowledge of parsing standards.
Culture & Benefits
- Remote-friendly and flexible work culture.
- Market leader in compensation and equity awards.
- Comprehensive physical and mental wellness programs.
- Competitive vacation and holidays for recharge.
- Professional development opportunities for all employees.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →