Detection and Response Engineer

Emploi pas sur LinkedIn

🕒 il y a 16 jours

🇺🇸 États-Unis – Télétravail

💵 $80 000 - $134 000 / an

⏰ Temps Plein

🟢 Junior

🟡 Intermédiaire

👷🏻‍♀️ Ingénieur

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Coalfire

Coalfire

1001 - 5000 employés

Fondée en 2001

💼 Conseil

🏥 Santé

📦 Logistique

Consulting • Healthcare • Logistics

Coalfire est un fournisseur de services de cybersécurité qui aide les entreprises à améliorer leur résilience en matière de sécurité et à simplifier la conformité réglementaire. La société propose des services dirigés par des experts, incluant des programmes de cybersécurité axés sur les menaces, l'automatisation de la conformité, la gestion des risques et des services de conseil en sécurité, couvrant divers secteurs tels que les services financiers, la santé, le commerce de détail et la technologie. Coalfire est réputée pour son expertise en matière de hackers et de défenseurs, et ses plateformes sont conçues pour renforcer la résilience cybernétique des clients, réduire les surfaces d'attaque et accélérer l'atteinte d'objectifs de conformité comme FedRAMP et HITRUST.

Description

• Collect, analyze, and operationalize threat intelligence to inform proactive detection and threat‑hunting activities, driving measurable security posture improvements across client environments. • Develop, optimize, and maintain custom detection and threat‑hunting queries across two or more SIEM platforms, tuning alerts for improved fidelity and building dashboards and saved searches that support repeatable, operational use cases. • Plan and lead cyclical, hypothesis‑driven threat hunts using threat intelligence and behavior‑based analytics; identify detection gaps and telemetry blind spots, and translate hunt outcomes into detection improvements, alert tuning, and updated runbooks.

🎯 Exigences

• 2–4 years of experience operating within large‑scale enterprise security environments, including exposure to cloud‑hosted or hybrid infrastructures. • Foundational working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and how cloud telemetry is leveraged for security monitoring and investigations. • Hands‑on experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response environment. • Experience independently monitoring, validating, and escalating SIEM alerts in accordance with documented runbooks, SLAs, and severity thresholds. • Proven ability to independently investigate and respond to security alerts, performing deep‑dive analysis across multiple log sources to determine scope, root cause, and impact. • Experience escalating confirmed or high‑confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers. • Experience conducting structured and cyclical threat‑hunting activities using hypothesis‑driven and behavior‑based methodologies. • Ability to leverage threat intelligence to understand threat actor tradecraft, attack chains, and expected telemetry, and apply that knowledge to investigations and hunts. • Hands‑on experience developing, optimizing, and maintaining custom detection and threat‑hunting queries in at least two SIEM platforms, and translating investigative requirements into performant, reusable query logic. • Experience identifying detection gaps, telemetry blind spots, and data quality issues, and translating findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs. • Excellent communication, organizational, and problem-solving skills, with the ability to convey complex technical information clearly. • Strong documentation skills for creating technical diagrams, written descriptions, and other supporting materials. • Demonstrated ability to work both independently and as a member of a team, maintaining a professional attitude and demeanor. • Critical thinking skills to balance robust security requirements against mission objectives. • Proven track record of adapting quickly and efficiently in fast-paced, dynamic environments. • Experience utilizing a Detection-as-Code framework • Experience working with NIST 800-53 environments • **__REQUIRED CERTIFICATIONS:__** • At least one of the following: • Splunk Enterprise Certified Administrator • Splunk Enterprise Security Certified Administrator • SumoLogic Administrator • Microsoft Security Operations Associate • Elastic Stack Certified Administrator

🏖️ Avantages

• paid parental leave • flexible time off • certification and training reimbursement • digital mental health and wellbeing support membership • comprehensive insurance options

Postuler Maintenant

Emplois Similaires

🕒 il y a 16 jours

NV5

1001 - 5000

💼 Conseil

🏗️ Construction

📦 Logistique

Substation Engineer providing technical support for high voltage substation projects. Collaborating with multidisciplinary teams to ensure successful project execution.

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 16 jours

Precise Software Solutions, Inc.

51 - 200

🏛️ Gouvernement

🤖 Intelligence artificielle

🤝 B2B

Release Train Engineer managing the delivery of a major FDA modernization initiative. Coordinating across teams and facilitating Agile processes within a cloud-native platform environment.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 16 jours

Five9

1001 - 5000

☁️ SaaS

🤖 Intelligence artificielle

📡 Télécommunications

WEM AQM Prompt Engineer designing and optimizing evaluation prompts for Five9's AQM product. Collaborating with clients and teams to enhance AI-driven quality evaluations.

🇺🇸 États-Unis – Télétravail

💵 $70 400 - $195 700 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 16 jours

Wave Mobile Money

501 - 1000

💼 Conseil

📦 Logistique

💳 Fintech

Sr Endpoint Engineer managing MDM platforms across various operating systems for Wave. Responsible for endpoint security, device lifecycle management, and automation in a fast-growth environment.

🇺🇸 États-Unis – Télétravail

💵 $96 500 - $133 100 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Android

Jamf

Linux

MacOS

🕒 il y a 16 jours

Snowflake

5001 - 10000

💼 Conseil

📣 Marketing

Account Engineer at Snowflake delivering technical expertise and customer engagement. Supporting customer engagements while collaborating with diverse audiences and technical teams.

🇺🇸 États-Unis – Télétravail

💵 $140 000 - $183 750 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis