SIEM Detection Engineer

🕒 Agosto 17

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $111.900 - $162.300 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🦅 Patrocina Visto H1B

infoinfo

👻 Score fantasma 0%

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Expel

Expel

201 - 500 funcionários

Fundada em 2016

🔒 Cibersegurança

☁️ SaaS

Cybersecurity • SaaS • Technology

A Expel é uma empresa líder em cibersegurança especializada em serviços de Detecção e Resposta Gerenciadas (MDR). Eles oferecem uma variedade de soluções, incluindo investigação de phishing, caça a ameaças e priorização de vulnerabilidades, adaptadas para organizações de todos os tamanhos com proteção 24x7. A Plataforma de Operações de Segurança da Expel, Expel Workbench™, integra-se com a tecnologia existente para aprimorar as operações de segurança. Sua equipe de especialistas e tecnologia avançada ajudam a reduzir o ruído de alertas, responder rapidamente a incidentes e melhorar a postura geral de segurança, permitindo que as organizações se concentrem em suas atividades principais sem se preocupar com ameaças de cibersegurança.

Descrição

• Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing • Develop and validate detection content for defined security use cases during onboarding and as environments evolve • Optimize SIEM performance and cost by tuning detections, reducing alert noise, and improving ingestion efficiency • Contribute to Expel’s proprietary professional services detection library • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources • Partner with Detection Engineering and the SOC to hand off environments for co-managed operations • Work with SOC analysts to improve rule and alert fidelity and actionability • Track the evolving threat landscape and turn it into new detection development • Contribute repeatable processes, templates, and tooling to improve delivery quality and consistency

🎯 Requisitos

• Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR • 3+ years writing, deploying, and tuning custom detections using common datasets such as Windows Event Logs, auditd, and CloudTrail • SIEM migration experience translating detection logic between platforms and re-pointing log sources • Working knowledge of attacker tactics, techniques, and the MITRE ATT&CK framework • Fundamentals across Windows, macOS, and Linux • Networking basics, including TCP/IP and OSI • Working knowledge of cloud IAM models and platforms • Basic proficiency with Python, Go, or similar • Comfort using Git/GitHub for version control of detection content, scripts, and templates • Curiosity, strong ownership, and appetite for growth • Willingness to travel up to 20% • Must be authorized to work in the United States • Immigration visa sponsorship is not currently available • Preferred/bonus: SIEM or vendor certifications; Sigma; detection-as-code and CI/CD; industry security certifications; bachelor’s degree in Computer Science or Information Security

🏖️ Benefícios

• Bonus eligibility • Equity • Unlimited PTO • Work location flexibility • Up to 24 weeks of parental leave • Really excellent health benefits • Professional development runway • Exposure to complex, high-stakes detection and SIEM problems • Career growth through ownership of meaningful outcomes • Ground-floor opportunity in a new professional services function

Candidatar-se

Vagas Similares

🕒 Agosto 17

ASR Group

5001 - 10000

🍽️ Alimentos e Bebidas

🏭 Manufatura

🌾 Agricultura

Lead complex capital programs for ASR Group, the world’s largest cane-sugar refiner and marketer. Oversee engineering, budgets, commissioning, compliance, and cross-functional project delivery across refinery operations.

🗣️🇺🇸🇬🇧 Inglês obrigatório

PMP

🕒 Agosto 17

Sargent & Lundy

1001 - 5000

🏗️ Construção

🎖️ Defesa

⚡ Energia

Lead structural engineering for Sargent & Lundy’s nuclear facilities and plant modernization projects. Guiding teams through safety-related analysis, design calculations, specifications, and client coordination.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $118.023 - $180.313 / ano

⏰ Tempo Integral

🟠 Sênior

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Agosto 17

Sargent & Lundy

1001 - 5000

🏗️ Construção

🎖️ Defesa

⚡ Energia

Senior structural engineer analyzing safety-related nuclear structures for Sargent & Lundy. Leading design calculations, blast and seismic analysis, and engineering automation for clean-energy projects.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $84.762 - $129.498 / ano

⏰ Tempo Integral

🟠 Sênior

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Agosto 17

General Dynamics Ordnance and Tactical Systems

1001 - 5000

🚀 Aeroespacial

🎖️ Defesa

🏭 Manufatura

Project Engineer II leading solid rocket motor design, manufacturing, and delivery projects. Coordinating integrated teams, schedules, budgets, resources, and technical customer requirements for aerospace and defense products.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $80.000 - $108.000 / ano

⏰ Tempo Integral

🟢 Júnior

🟡 Pleno

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Agosto 17

NetCov

201 - 500

🔒 Cibersegurança

🤝 B2B

💼 Consultoria

Service Desk Engineer delivering managed IT and cybersecurity services for NetCov clients. Managing infrastructure, resolving complex issues, and guiding managed services teams.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $61.875 - $82.500 / ano

💰 Private equity em 2022-11

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👷🏻‍♀️ Engenheiro

🗣️🇺🇸🇬🇧 Inglês obrigatório

AWS

Azure

Cloud

DNS

Firewalls

Switching