Rearc

Rearc is a boutique Cloud Software & Services firm with engineers that have years of experience shaping the cloud journey of large scale enterprises. Our engineers are skilled at planning application migrations to the cloud and building cloud-native application environments and patterns for the future. We build strategic partnerships with our enterprise customers to enable long term success in the cloud.

Senior Cybersecurity Engineer 🇺🇸

Security EngineerSecurity EngineerFull TimeRemoteTeam 51Since 2016

Location

United States

Posted

4 days ago

Salary

Not specified

SIEMSOAREDRNDRPythonSQLApache SparkDetection As CodeDev Sec OpsCloud SecurityData EngineeringData ScienceStatistical AnalysisIncident ResponseInformation TechnologyOperational Technology

Job Description


Role Overview


Rearc is looking for a Cybersecurity Threat Detection Engineer with proactive communication skills, a foundation in DevSecOps, Detection-As-Code, deep purple team technical expertise, and an entrepreneurial approach to join our growing Cybersecurity practice. This role involves partnering with Rearc customers to design cutting-edge detection strategies and support the development of top-tier, modern cybersecurity monitoring programs. You will craft tailored security detections to strengthen our clients' cybersecurity efforts by leveraging Security Information and Event Management (SIEM), Security Orchestration Automation and Response (SOAR), Endpoint Detection and Response (EDR), and Network Detection and Response (NDR) services.

What You Bring

  • Enthusiasm about developing and evangelizing services in the cyber space. 
  • Strong cloud, security, SIEM and data engineering fundamentals.

What You'll Do

  • Utilize NDR, EDR, real-time streaming, and SIEM technologies to develop robust threat detection capabilities.
  • Build and optimize detection rules leveraging real-time data streaming to enhance detection accuracy.
  • Design enrichment pipelines and automation workflows to enhance the precision of threat detections.
  • Develop correlation logic and automated processes to create high-fidelity threat alerts.
  • Build compliance and recoverability of customer Data Analytics solutions, including SOPs, data onboarding, normalization, enrichment, and system maintenance.
  • Create automation playbooks for incident triage and response.
  • Align detection content with customer-specific Use Case Frameworks and provide metrics on cybersecurity threats impacting their environment.
  • Collaborate with customer cybersecurity teams to cover gaps and enhance enterprise posture.
  • Support enterprise Cybersecurity, Information Technology (IT), and Operational Technology (OT) teams by providing dashboards and other data exploration tools.
  • Stay continually aware of emerging cybersecurity threats and trends, adapting detection strategies as needed.
  • Work closely with customer teams, including Cybersecurity Operations Center (CSOC), Operational Technology (OT), and Incident Response (IR) teams, to ensure detections are actionable and relevant.
  • Provide feedback to improve the customer's security framework and overall security monitoring strategy.

In this role, you will combine technical expertise with continual situational awareness of emerging threats, driving client success while staying at the cutting edge of cyber security innovations.

Qualifications

  • 5-8 years of experience in Cybersecurity with a focus on:
    • Log streaming
    • Cybersecurity data lakes and data warehousing
    • SOAR engineering
    • SIEM engineering, administration, architecture, and operations
    • Data science, statistical analysis, and threat detection development
    • Integrating disparate IT, OT, and business applications into SIEM systems
  • Bachelor's degree in Management Information Systems, Computer Science, or a related field
  • A strong passion for Cybersecurity and a commitment to staying current with industry trends, best practices, and tools
  • Proven experience in documenting, socializing, and operationalizing Cybersecurity technologies and processes
  • Prior programming experience in Python, SQL, and Apache Spark
  • Solid understanding of common attack techniques and their practical applications
  • Demonstrated ability to work effectively across multiple teams, building cross-functional relationships with individuals of varying technical expertise
  • A self-starter with a proven ability to thrive in fast-paced environments
  • Strong technical communication skills, both written and verbal


Nice To Have:

  • Prior experience with platforms like Databricks, Cribl, Tines, or other cybersecurity lakehouse providers


Some More About Us

At Rearc, our mission is straightforward - empower engineers with the best tools possible to make an impact within their industry. We pride ourselves on fostering an environment where creativity flourishes, bureaucracy is non-existent, and individuals are encouraged to challenge the status quo. We're not just a company; we're a community of problem-solvers dedicated to improving the lives of fellow software engineers.

Our commitment is simple - finding the right fit for our team and cultivating a desire to make things better. If you're a cloud professional intrigued by our problem space and eager to make a difference, you've come to the right place. Join us, and let's solve problems together!


Related Categories

Related Job Pages

More Security Engineer Jobs

Lead Cybersecurity Engineer 🇺🇸

Rearc

Rearc is a boutique Cloud Software & Services firm with engineers that have years of experience shaping the cloud journey of large scale enterprises. Our engineers are skilled at planning application migrations to the cloud and building cloud-native application environments and patterns for the future. We build strategic partnerships with our enterprise customers to enable long term success in the cloud.

Security Engineer4 days ago
Full TimeRemoteTeam 51Since 2016

The role involves partnering with customers to design cutting-edge detection strategies and support the development of modern cybersecurity monitoring programs using SIEM, SOAR, EDR, and NDR services. Responsibilities include utilizing these technologies to build robust threat detection capabilities, optimizing rules, designing enrichment pipelines, and creating automation playbooks for incident response.

PythonSQLApache SparkSIEMSOAREDRNDRDevSecOpsData EngineeringCloud SecurityThreat DetectionLog StreamingData WarehousingStatistical Analysis
United States

Security Engineer

Wraithwatch Corporation

Wraithwatch was founded by security engineers from SpaceX, Palantir, and Anduril to build the next generation of AI-powered cyber defense systems for the United States and its allies. We are deployed today to customers spanning Fortune 500, US Federal Government, commercial nuclear, aerospace, defense, maritime, and other emerging technology companies. Our core product is a cyber defense platform utilizing generative artificial intelligence agents to autonomously model a digital twin of an organization's entire IT and cybersecurity environment and analyze it for weaknesses, misconfigurations, and chains of possible attack.

Security Engineer4 days ago
Full TimeRemote

Security Engineers will plan and engineer the integration of various cybersecurity and IT tools into the core artificial intelligence engine, ensuring AI has access to common data models and function execution across disparate systems. They will also provide cybersecurity subject matter expertise to optimize autonomous reasoning and own the internal corporate cybersecurity posture across endpoints, cloud systems, and build pipelines.

PythonRustGoSIEMSOARXDREDRAPIIdentity and Access ManagementDevice ManagementDetection EngineeringCloud SecurityEndpoint Security
United States

Senior Security Engineer, Application Security

Turnkey

Secure, flexible, and scalable wallet infrastructure

Security Engineer4 days ago
Full TimeRemoteTeam 11-50Since 2022H1B Sponsor

The engineer will partner with Product and Engineering during design and development to ensure secure feature implementation, involving security reviews, product design input, and vulnerability auditing. Key tasks include developing automated tooling to scale security capabilities, defining application guardrails for secure development by default, and driving long-term improvements to prevent security issue recurrence.

Application SecurityThreat ModelingOWASPSANS/CWETypeScriptJavaScriptGoRustStatic AnalysisDynamic AnalysisPenetration TestingAWSGCPDockerKubernetesSDLCCryptography
United States
$175K - $275K / year

Senior Security Engineer, Corporate Security

Turnkey

Secure, flexible, and scalable wallet infrastructure

Security Engineer4 days ago
Full TimeRemoteTeam 11-50Since 2022H1B Sponsor

This foundational role involves designing, implementing, and managing security for corporate endpoints and distributed systems, including deploying the security stack and enforcing zero-trust principles. The engineer will also lead initiatives for risk reduction, respond to security incidents, and foster a strong security culture across the organization.

MDMEDRXDRIdentity and Access ManagementOktaAzure ADSAMLOAuthOIDCSCIMZero-trust architectureAWSGCPmacOS securityEndpoint hardeningVulnerability remediationIncident responseAutomationSecurity policies
United States
$175K - $275K / year