Senior Cybersecurity Detection & Threat Intelligence Engineer

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Solstice Advanced Materials

Solstice Advanced Materials

1001 - 5000 employees

Founded 2025

🚘 Automotive

🎖️ Defense

🏥 Healthcare

Automotive • Defense • Healthcare

Solstice Advanced Materials is a specialty materials company spun out of Honeywell’s Advanced Materials business in 2025. The company develops and supplies advanced chemical and polymer-based solutions — including low‑GWP refrigerants, ballistic protection fibers, semiconductor materials, and pharmaceutical packaging films — for industrial and institutional customers. Solstice focuses on applied materials science and thermal management technologies across sectors such as automotive, electronics, defense, and healthcare, offering custom formulations, compliance support, and global technical service.

📋 Description

• Design, implement, and continuously tune threat detections across SIEM, EDR/XDR, OT security platforms, and cloud-native security tooling • Own the end-to-end detection engineering lifecycle, including hypothesis development, rule authoring, validation, deployment, tuning, and retirement, aligned to MITRE ATT&CK across IT, OT, cloud, and identity environments • Operationalize threat intelligence by translating finished intelligence, IOCs, and adversary TTPs into actionable detection rules, hunt hypotheses, and automated enrichment workflows • Manage and maintain threat intelligence feeds and platforms, including ingestion, validation, confidence scoring, and expiration of IOC libraries • Build, maintain, and improve SOAR automation playbooks, enrichment pipelines, and detection workflows to increase alert fidelity and reduce analyst toil • Develop and maintain detection content for OT/ICS environments, including industrial protocol anomaly detection, Purdue model segmentation visibility, and OT-specific threat actor TTPs • Improve security telemetry quality and coverage by collaborating with infrastructure, network, cloud, OT, and platform engineering teams to onboard new log sources and validate data fidelity

🎯 Requirements

• Must reside in India; role approved for India-based candidates only • 7–10+ years of experience in cybersecurity focused on detection engineering, security operations, or threat intelligence • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or QRadar, including rule authoring, query development, and data onboarding • Deep understanding of adversary tactics, techniques, and procedures, with experience mapping detections to MITRE ATT&CK • Hands-on experience developing detection rules, correlation logic, behavioral analytics, and threshold-based alerting across multiple telemetry sources • Experience with SOAR platforms for automated enrichment pipelines, detection workflows, and threat intelligence operationalization • Strong scripting and automation skills in Python, PowerShell, or KQL for detection development, data parsing, and workflow automation • Experience with threat intelligence platforms for IOC lifecycle management, feed integration, and intelligence-to-detection operationalization • Preferred: experience building or maturing detection engineering programs, including backlog management, coverage gap analysis, and ATT&CK heatmap maintenance • Preferred: experience with OT/ICS security monitoring • Preferred: familiarity with threat intelligence integration and threat hunting methodologies • Preferred: familiarity with detection-as-code, version control for detection content, and automated rule testing pipelines • Preferred: knowledge of cloud-native security monitoring and identity telemetry • Preferred: relevant certifications such as GDAT, GCDE, GCIA, GCED, or equivalent credentials

Apply Now

Similar Jobs

🕒 Yesterday

Teladoc Health

5001 - 10000

🏥 Healthcare

👥 B2C

☁️ SaaS

Azure Security Lead securing Microsoft Azure environments for Teladoc Health’s virtual-care platform. Implementing cloud controls, monitoring, governance, and automation across Azure workloads.

Azure

Cloud

Terraform

Vault

🕒 Yesterday

Clario

5001 - 10000

🏥 Healthcare

💼 Consulting

📦 Logistics

Cybersecurity Engineer securing Clario’s clinical-trial endpoint data solutions through penetration testing, threat modeling, secure architecture reviews, and DevSecOps automation.

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform

Java

JavaScript

Kubernetes

Microservices

Python

SDLC

Go

🕒 6 days ago

Coupa Software

1001 - 5000

💼 Consulting

📦 Logistics

🏥 Healthcare

Lead Security Engineer securing Coupa’s AI-powered spend management cloud platform. Architecting cloud controls, automating security guardrails, and leading vulnerability response at scale.

AWS

Azure

Cloud

Google Cloud Platform

Kubernetes

Python

Terraform

Go

🕒 6 days ago

Coupa Software

1001 - 5000

💼 Consulting

📦 Logistics

🏥 Healthcare

Senior Security Engineer securing Coupa’s AI-powered spend management platform. Building multi-cloud controls, Kubernetes protections, vulnerability remediations, and compliance evidence.

AWS

Azure

Cloud

Google Cloud Platform

JavaScript

Kubernetes

Python

🕒 August 5

Sophos

1001 - 5000

💼 Consulting

🏥 Healthcare

🏭 Manufacturing

Senior incident responder leading ransomware and BEC investigations for Sophos, a global cybersecurity company. Directing customer engagements, forensic analysis, threat neutralization, reporting, and remediation guidance.

Cyber Security

Python

Splunk

SQL