Threat Detection Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Threat Detection Engineer: Building, deploying, and maintaining detection rules for security toolsets with an accent on SIEM, EDR, and security automation. Focus on creating SIGMA rules, analyzing security logs, and responding to incidents to protect the organization from cyber threats.
Location: Must be based in Overland Park, KS, USA
Salary: $86,000 - $103,000 yearly
Company
provides next-generation commercialization services to the life sciences industry, supporting biotech and pharmaceutical companies in bringing therapies to market.
What you will do
- Create and maintain threat detection rules, alerts, and dashboards using Splunk and SentinelOne.
- Analyze security logs and network traffic to identify and investigate potential security incidents.
- Administer applications within the security stack and streamline security processes.
- Contribute to the development and upkeep of the security detection database.
- Respond to security incidents, troubleshoot issues, and perform remediation.
- Collaborate with the security engineering team to enhance the overall security posture.
Requirements
- Must be based in Overland Park, KS, USA
- 3+ years of hands-on experience in detection engineering or security automation.
- Proficiency with EDR, SIEM, and Vulnerability Management technologies.
- Understanding of network security, operating systems, and cloud security.
- Experience with incident response techniques.
- Strong analytical, problem-solving, and communication skills.
Nice to have
- BS in Cybersecurity or related field.
- Experience with Python scripting and SIGMA rule creation in YAML.
- Knowledge of MITRE ATT&CK framework and SOAR platforms.
- Experience with cloud security platforms (GCP, AWS, Azure).
- Relevant security certifications such as Security+, GMON, or GCDA.
Culture & Benefits
- Commitment to diversity, equity, and inclusion.
- Competitive salary and benefits package.
- Supportive environment focused on patient outcomes and innovation.
- Opportunities for professional development and growth.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →