Detection and Response Engineer

🕒 Julho 21

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $80.000 - $134.000 / ano

⏰ Tempo Integral

🟢 Júnior

🟡 Pleno

👷🏻‍♀️ Engenheiro

🦅 Patrocina Visto H1B

infoinfo

👻 Score fantasma 0%

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Coalfire

Coalfire

1001 - 5000 funcionários

Fundada em 2001

💼 Consultoria

🏥 Saúde

📦 Logística

Consulting • Healthcare • Logistics

A Coalfire é uma fornecedora de serviços de cibersegurança que ajuda empresas a melhorarem sua resiliência em segurança e a simplificarem a conformidade regulatória. A empresa oferece serviços especializados, incluindo programas de cibersegurança focados em ameaças, automação de conformidade, gestão de riscos e serviços de consultoria em segurança em diversos setores, como serviços financeiros, saúde, varejo e tecnologia. A Coalfire é conhecida por sua expertise em hackers e defensores, e suas plataformas são projetadas para fortalecer a resiliência cibernética dos clientes, reduzir superfícies de ataque e acelerar o alcance de objetivos de conformidade como FedRAMP e HITRUST.

Descrição

• Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments. • Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases. • Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks.

🎯 Requisitos

• 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures. • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations. • Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment. • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds. • Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact. • Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers. • Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies. • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts. • Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic. • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs. • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly. • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials. • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor. • Critical thinking skills to balance robust security requirements against mission objectives. • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments. • Experience utilizing a Detection-as-Code framework • Experience working with NIST 800-53 environments • **__REQUIRED CERTIFICATIONS:__** • At least one of the following: • Splunk Enterprise Certified Administrator • Splunk Enterprise Security Certified Administrator • SumoLogic Administrator • Microsoft Security Operations Associate • Elastic Stack Certified Administrator

🏖️ Benefícios

• paid parental leave • flexible time off • certification and training reimbursement • digital mental health and wellbeing support membership • comprehensive insurance options

Candidatar-se

Vagas Similares

🕒 Julho 21

NV5

1001 - 5000

💼 Consultoria

🏗️ Construção

📦 Logística

Substation Engineer providing technical support for high voltage substation projects. Collaborating with multidisciplinary teams to ensure successful project execution.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 21

Five9

1001 - 5000

☁️ SaaS

🤖 Inteligência Artificial

📡 Telecomunicações

WEM AQM Prompt Engineer designing and optimizing evaluation prompts for Five9's AQM product. Collaborating with clients and teams to enhance AI-driven quality evaluations.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $70.400 - $195.700 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 21

Wave Mobile Money

501 - 1000

💼 Consultoria

📦 Logística

💳 Fintech

Sr Endpoint Engineer managing MDM platforms across various operating systems for Wave. Responsible for endpoint security, device lifecycle management, and automation in a fast-growth environment.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $96.500 - $133.100 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Android

Jamf

Linux

MacOS

🕒 Julho 21

Lightology

51 - 200

💼 Consultoria

🏭 Manufatura

🛒 Varejo

Web Application Firewall Engineer at Lightology ensuring security throughout the SDLC for web applications. Focused on vulnerability management, secure coding standards, and web application firewalls.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $100.000 - $120.000 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório

Firewalls

SDLC

🕒 Julho 21

Davenergy Solutions

51 - 200

🏥 Saúde

💼 Consultoria

📦 Logística

Fire Protection Engineer supporting U.S. Department of Veterans Affairs and Department of Defense projects. Performing design reviews, inspections, and compliance certifications for fire safety systems.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório