Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Detection Engineer (Cybersecurity): Building and maintaining detection and incident response capabilities to secure AI infrastructure with an accent on automation and scaling security efforts. Focus on developing detection rules, triaging alerts, and integrating frontier AI models to reduce manual security work.
Location: In-country role with a strong preference for London, UK
Company
AI research and product company transforming how we interact with technology through leading AI audio foundational models.
What you will do
- Build and maintain security detection and incident response capabilities.
- Automate security efforts and reduce manual work by leveraging frontier AI models.
- Triage security alerts, conduct investigations, and lead response efforts.
- Develop, tune, and maintain security detection rules and alerts.
- Manage security monitoring across GCP, JAMF MDM, Google Workspace, and Okta.
- Translate threat intelligence and common attack techniques into actionable detections.
Requirements
- Proven experience in incident response and security operations.
- Strong background in detection engineering and tuning alerts.
- Hands-on experience with Google SecOps (Chronicle), including data onboarding and parsing.
- Proficiency in cloud security monitoring within Google Cloud (GCP) and Security Command Center (SCC).
- Solid scripting skills in Python and Bash for automating security tasks.
- Deep understanding of MITRE ATT&CK and NIST Cybersecurity Frameworks.
Culture & Benefits
- Opportunity to define the trajectory of AI in a high-velocity, innovative culture.
- Annual discretionary stipend for professional learning and development.
- Annual discretionary stipend for social travel to meet with colleagues.
- Annual company offsite in international locations.
- Monthly co-working stipend for those not located near main hubs.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →