Detection and Response Engineer

Stelle nicht auf LinkedIn

🕒 vor 17 Tagen

🇺🇸 Vereinigte Staaten – Remote

💵 $80.000 - $134.000 / Jahr

⏰ Vollzeit

🟢 Junior

🟡 Mittelstufe

👷🏻‍♀️ Ingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Coalfire

Coalfire

1001 - 5000 Mitarbeiter

Gegründet 2001

💼 Beratung

🏥 Gesundheitswesen

📦 Logistik

Consulting • Healthcare • Logistics

Coalfire ist ein Anbieter von Cybersecurity-Dienstleistungen, der Unternehmen dabei hilft, ihre Sicherheitsresilienz zu verbessern und die Einhaltung von Vorschriften effizienter zu gestalten. Das Unternehmen bietet durch Experten geführte Dienstleistungen an, darunter bedrohungsorientierte Cybersecurity-Programme, Automatisierung der Compliance, Risikomanagement und Sicherheitsberatung in verschiedenen Branchen wie Finanzdienstleistungen, Gesundheitswesen, Einzelhandel und Technologie. Coalfire ist bekannt für seine Expertise sowohl auf der Hacker- als auch auf der Verteidigerseite, und seine Plattformen sind darauf ausgelegt, die Cyber-Resilienz der Kunden zu stärken, Angriffsflächen zu reduzieren und die Erreichung von Compliance-Zielen wie FedRAMP und HITRUST zu beschleunigen.

Beschreibung

• Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments. • Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases. • Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks.

🎯 Anforderungen

• 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures. • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations. • Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment. • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds. • Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact. • Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers. • Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies. • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts. • Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic. • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs. • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly. • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials. • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor. • Critical thinking skills to balance robust security requirements against mission objectives. • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments. • Experience utilizing a Detection-as-Code framework • Experience working with NIST 800-53 environments • **__REQUIRED CERTIFICATIONS:__** • At least one of the following: • Splunk Enterprise Certified Administrator • Splunk Enterprise Security Certified Administrator • SumoLogic Administrator • Microsoft Security Operations Associate • Elastic Stack Certified Administrator

🏖️ Vorteile

• paid parental leave • flexible time off • certification and training reimbursement • digital mental health and wellbeing support membership • comprehensive insurance options

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 17 Tagen

NV5

1001 - 5000

💼 Beratung

🏗️ Bauwesen

📦 Logistik

Substation Engineer providing technical support for high voltage substation projects. Collaborating with multidisciplinary teams to ensure successful project execution.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 17 Tagen

Precise Software Solutions, Inc.

51 - 200

🏛️ Regierung

🤖 Künstliche Intelligenz

🤝 B2B

Release Train Engineer managing the delivery of a major FDA modernization initiative. Coordinating across teams and facilitating Agile processes within a cloud-native platform environment.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 17 Tagen

Five9

1001 - 5000

☁️ SaaS

🤖 Künstliche Intelligenz

📡 Telekommunikation

WEM AQM Prompt Engineer designing and optimizing evaluation prompts for Five9's AQM product. Collaborating with clients and teams to enhance AI-driven quality evaluations.

🇺🇸 Vereinigte Staaten – Remote

💵 $70.400 - $195.700 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 17 Tagen

Wave Mobile Money

501 - 1000

💼 Beratung

📦 Logistik

💳 Fintech

Sr Endpoint Engineer managing MDM platforms across various operating systems for Wave. Responsible for endpoint security, device lifecycle management, and automation in a fast-growth environment.

🇺🇸 Vereinigte Staaten – Remote

💵 $96.500 - $133.100 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

Android

Jamf

Linux

MacOS

🕒 vor 17 Tagen

Snowflake

5001 - 10000

💼 Beratung

📣 Marketing

Account Engineer at Snowflake delivering technical expertise and customer engagement. Supporting customer engagements while collaborating with diverse audiences and technical teams.

🇺🇸 Vereinigte Staaten – Remote

💵 $140.000 - $183.750 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich