SIEM Detection Engineer

🕒 vor 7 Tagen

🇺🇸 Vereinigte Staaten – Remote

💵 $111.900 - $162.300 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🦅 H1B-Visum-Sponsor

infoinfo

👻 Geisterscore 0%

infoinfo

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Expel

Expel

201 - 500 Mitarbeiter

Gegründet 2016

🔒 Cybersecurity

☁️ SaaS

Cybersecurity • SaaS • Technology

Expel ist ein führendes Cybersecurity-Unternehmen, das sich auf Managed Detection and Response (MDR) Services spezialisiert hat. Sie bieten eine Vielzahl von Lösungen wie Phishing-Untersuchungen, Threat Hunting und Priorisierung von Schwachstellen an, die für Organisationen jeder Größe maßgeschneidert sind und einen 24/7-Schutz bieten. Die Sicherheitsplattform von Expel, Expel Workbench™, integriert sich in bestehende Technologien, um die Sicherheitsoperationen zu verbessern. Ihr Expertenteam und die fortschrittliche Technologie helfen dabei, Alarmmeldungen zu reduzieren, schnell auf Vorfälle zu reagieren und die allgemeine Sicherheitslage zu verbessern, wodurch es Organisationen ermöglicht wird, sich auf ihre Kernaktivitäten zu konzentrieren, ohne sich um Cybersecurity-Bedrohungen sorgen zu müssen.

Beschreibung

• Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing • Develop and validate detection content for defined security use cases during onboarding and as environments evolve • Optimize SIEM performance and cost by tuning detections, reducing alert noise, and improving ingestion efficiency • Contribute to Expel’s proprietary professional services detection library • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources • Partner with Detection Engineering and the SOC to hand off environments for co-managed operations • Work with SOC analysts to improve rule and alert fidelity and actionability • Track the evolving threat landscape and turn it into new detection development • Contribute repeatable processes, templates, and tooling to improve delivery quality and consistency

🎯 Anforderungen

• Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR • 3+ years writing, deploying, and tuning custom detections using common datasets such as Windows Event Logs, auditd, and CloudTrail • SIEM migration experience translating detection logic between platforms and re-pointing log sources • Working knowledge of attacker tactics, techniques, and the MITRE ATT&CK framework • Fundamentals across Windows, macOS, and Linux • Networking basics, including TCP/IP and OSI • Working knowledge of cloud IAM models and platforms • Basic proficiency with Python, Go, or similar • Comfort using Git/GitHub for version control of detection content, scripts, and templates • Curiosity, strong ownership, and appetite for growth • Willingness to travel up to 20% • Must be authorized to work in the United States • Immigration visa sponsorship is not currently available • Preferred/bonus: SIEM or vendor certifications; Sigma; detection-as-code and CI/CD; industry security certifications; bachelor’s degree in Computer Science or Information Security

🏖️ Vorteile

• Bonus eligibility • Equity • Unlimited PTO • Work location flexibility • Up to 24 weeks of parental leave • Really excellent health benefits • Professional development runway • Exposure to complex, high-stakes detection and SIEM problems • Career growth through ownership of meaningful outcomes • Ground-floor opportunity in a new professional services function

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 7 Tagen

ASR Group

5001 - 10000

🍽️ Lebensmittel & Getränke

🏭 Fertigung

🌾 Landwirtschaft

Lead complex capital programs for ASR Group, the world’s largest cane-sugar refiner and marketer. Oversee engineering, budgets, commissioning, compliance, and cross-functional project delivery across refinery operations.

🗣️🇺🇸🇬🇧 Englisch erforderlich

PMP

🕒 vor 7 Tagen

Sargent & Lundy

1001 - 5000

🏗️ Bauwesen

🎖️ Verteidigung

⚡ Energie

Lead structural engineering for Sargent & Lundy’s nuclear facilities and plant modernization projects. Guiding teams through safety-related analysis, design calculations, specifications, and client coordination.

🇺🇸 Vereinigte Staaten – Remote

💵 $118.023 - $180.313 / Jahr

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 7 Tagen

Sargent & Lundy

1001 - 5000

🏗️ Bauwesen

🎖️ Verteidigung

⚡ Energie

Senior structural engineer analyzing safety-related nuclear structures for Sargent & Lundy. Leading design calculations, blast and seismic analysis, and engineering automation for clean-energy projects.

🇺🇸 Vereinigte Staaten – Remote

💵 $84.762 - $129.498 / Jahr

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 7 Tagen

General Dynamics Ordnance and Tactical Systems

1001 - 5000

🚀 Luft- und Raumfahrt

🎖️ Verteidigung

🏭 Fertigung

Project Engineer II leading solid rocket motor design, manufacturing, and delivery projects. Coordinating integrated teams, schedules, budgets, resources, and technical customer requirements for aerospace and defense products.

🇺🇸 Vereinigte Staaten – Remote

💵 $80.000 - $108.000 / Jahr

⏰ Vollzeit

🟢 Junior

🟡 Mittelstufe

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 7 Tagen

NetCov

201 - 500

🔒 Cybersecurity

🤝 B2B

💼 Beratung

Service Desk Engineer delivering managed IT and cybersecurity services for NetCov clients. Managing infrastructure, resolving complex issues, and guiding managed services teams.

🇺🇸 Vereinigte Staaten – Remote

💵 $61.875 - $82.500 / Jahr

💰 Private equity im 2022-11

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

AWS

Azure

Cloud

DNS

Firewalls

Switching