Requirements:
- Experience building / maturing a detection engineering program
- Hands-on security operations experience working within a modern zero trust oriented cloud / SaaS-heavy environment
- Strong understanding of incident response best practices with practical experience responding to moderate to complex security incidents
- Experience identifying / building new detection use cases
- Ability to collect / analyze large sets of structured / unstructured data from disparate sources
- Solid experience using SIEM tools (Splunk) for security investigations
- Experience using various security tools (EDR, web proxy, IDaaS etc) to assist with an investigation
- Strong networking and systems knowledge with a good understanding of macOS and Windows internals
- Experience working collaboratively to define and implement security policies, procedures, and controls
- Experience providing internal security consultancy / advice to other teams within the company
- Experience writing code (Python/Java) to solve problems, facilitate easier data analysis, and to automate security tasks
- Acutely aware of industry security trends, advisories, news, and general research
Nice to Haves:
- Deep knowledge of macOS and Windows internals and practical experience using it to secure such systems
- Experience in detection engineering processes / behaviors
- Experience monitoring / securing AWS, GCP, or Azure cloud environments
- Knowledge of containerization software and how to secure them (Docker, Kubernetes, OpenStack)
- Experience using tools like Splunk & Snowflake
- Experience using automation tools like Tines & Splunk SOAR
- Experience conducting data analysis using tools such as R, Tableau, PowerBI, Jupyter Notebook
What You'll Be Doing:
- Build a threat detection engineering program (full lifecycle)
- Build attack simulation scenarios, detection use cases & test their effectiveness
- Leverage an automation first mindset to work smarter / more efficiently
- Help respond when needed to critical security incidents
- Consult stakeholders on security-related subjects ranging from general OpSec, infrastructure architecture etc
Perks and Benefits:
We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don't hesitate to apply - we'd love to hear from you.
If you need accommodations or assistance due to a disability, please reach out to us using this form. This information will be treated as confidential and used only for the purpose of determining an appropriate accommodation for the interview process.