Senior SIEM Detection Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior SIEM Detection Engineer (Cybersecurity): Designing, implementing, and maintaining high‑fidelity detection content within cloud-based SIEM solutions with an accent on data ingestion, normalization, and rule tuning. Focus on reducing false positives, mapping detections to MITRE ATT&CK, and integrating SIEM with SOAR workflows to enhance incident response.
Location: Remote (United States)
Salary: $120,000 – $150,000 per year
Company
builds platforms for digital business, integrating cloud infrastructure, automation, and analytics to drive digital transformation for enterprises.
What you will do
- Lead detection content development in SIEM platforms including Elastic, Palo XSIAM, and Crowdstrike.
- Create, tune, and manage the lifecycle of detection rules and analytic use cases mapped to the MITRE ATT&CK framework.
- Define and maintain data models, normalization, and enrichment strategies to ensure high-quality detection signals.
- Collaborate with SOAR engineering to integrate SIEM detections with Swimlane workflows for automated triage and response.
- Onboard new data sources by defining logging, parsing, and normalization requirements with client IT teams.
- Perform data mining and exploratory analysis of log sources to uncover anomalous activity and undetected attack patterns.
Requirements
- Must be based in the United States.
- 2–4 years of experience in Security Detection Engineering, Security Automation, or related disciplines.
- Proficiency with Elastic Security and its core components (Elasticsearch, Logstash, Kibana, Filebeat, Elastic Agent).
- Experience writing Python scripts to automate detection-related tasks and data quality checks.
- Hands-on experience with IDS, Firewalls, SOAR, and EDR technologies.
- Bachelor’s Degree in Computer Science, Information Security, or equivalent professional experience.
Nice to have
- Professional certifications such as CISSP, GCIA, GCIH, GPYC, GMON, GCDA, or Elastic Certified Engineer.
Culture & Benefits
- Comprehensive Medical, Dental, and Vision Insurance.
- 401(k) retirement plan.
- Paid company holidays, PTO, and parental/caregiver leave.
- Access to a multi-million-dollar lab for testing and technology experimentation.
- Support for continuous learning through sponsored certifications and cross-department training.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →