1 день назад
Threat Detection Analyst (Expert)
70 000 - 140 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Threat Detection Analyst (Expert) (Cybersecurity): Developing, validating, and maintaining high-fidelity threat detections across SIEM, XDR, EDR, cloud, and network security platforms with an accent on threat intelligence, adversary tradecraft, and enterprise telemetry. Focus on MITRE ATT&CK-aligned detection engineering, purple team validation, coverage gap analysis, and tuning logic to reduce false positives and false negatives.
Location: Onsite at a corporate office in Detroit, Dallas, Columbus, Pittsburgh, Minnetonka, or Atlanta, United States.
Salary: $70,000–$140,000 annual base salary, plus eligibility for applicable incentive compensation.
Company
is a banking organization providing financial services and operating enterprise cybersecurity functions.
What you will do
- Design, develop, test, deploy, maintain, and tune threat detections across SIEM, XDR, EDR, cloud, and network security platforms.
- Analyze threat intelligence, adversary behaviors, attack techniques, security telemetry, and log sources to identify detection opportunities.
- Develop detection use cases, correlation rules, anomaly detections, behavioral detections, and telemetry requirements.
- Validate detections through threat simulations, purple team exercises, adversary emulation, and attack replay testing.
- Assess detection coverage and gaps, maintain documentation and coverage mappings, and report detection health and performance metrics.
- Collaborate with Incident Response, Threat Intelligence, Security Engineering, and IT Operations teams, while mentoring junior analysts.
Requirements
- At least 5 years of cybersecurity experience and at least 1 year of data analytics experience in threat detection.
- High school diploma or 8+ additional years of equivalent experience; a bachelor's degree or equivalent experience is preferred.
- Experience developing, testing, deploying, and maintaining enterprise threat detections based on MITRE ATT&CK, threat intelligence, and adversary behaviors.
- Experience with security telemetry, log analytics, detection coverage analysis, and reducing false positives while maintaining detection efficacy.
- Experience or knowledge involving platforms such as Palo Alto Cortex XSIAM, Microsoft Sentinel, Splunk, or Microsoft Defender XDR, and analytics languages such as KQL, SPL, XQL, or SQL.
- Occasional travel may be required, at less than 10%.
Nice to have
- Familiarity with detection-as-code and version-controlled detection development.
- Experience with threat hunting, attack simulation, adversary emulation, or purple team methodologies.
- Knowledge of Windows, Linux, macOS, Active Directory, Azure AD/Entra ID, cloud security telemetry, network protocols, and cybersecurity frameworks including Cyber Kill Chain and NIST CSF.
- Scripting and automation experience with Python, PowerShell, Bash, or similar languages.
Culture & Benefits
- Office-based work environment with collaboration across cybersecurity and IT teams.
- Health insurance, wellness programs, life and disability insurance, and retirement savings plan.
- Paid leave programs, paid holidays, and paid time off.
- Position is exempt from overtime eligibility.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 часов назад
Managed SIEM Detection Engineer (Cybersecurity)
111 900 - 162 300$
6 дней назад
Senior Security Analyst, Detection & Response (Cybersecurity)
100 000 - 130 000$
CrowdStrike
3 дня назад
Threat Hunter, FedCloud (Remote)
85 000 - 120 000$
5 дней назад
Security Engineer (AI)
150 000 - 250 000$
5 дней назад
Threat Detection & Response Engineer, Senior (High Level Clearance Required)
119 323 - 202 850$
4 дня назад
Cyber Security Analyst
100 000 - 130 000$