Threat Detection Engineer

Security EngineerSecurity EngineerFull TimeRemote

Location

United States

Posted

4 days ago

Salary

$500K / year

PythonSIEMGoogle Sec OpsPandasJupyter NotebooksPacket Capture AnalysisLOG AnalysisThreat DetectionIncident ResponseThreat HuntingThreat IntelligenceDetection AS CodeAutomation

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

We are seeking a talented, motivated Threat Detection Engineer to join our global team. This individual will be a self-starter excited to take on ownership of complex projects with a wide degree of autonomy. This role is unique in its schedule, providing critical weekend coverage during local daytime hours in exchange for a flexible schedule during the work week.

As a Threat Detection Engineer, you will be responsible for designing, implementing, and maintaining systems and logic to identify and neutralize sophisticated cyber threats. You will operate within a high-fidelity Detection-as-Code environment, moving beyond traditional SOC tiers to act as an elite, end-to-end security engineer.

Responsibilities:

  • Detection Engineering: Develop, tune, and deploy high-fidelity detections and rules to prevent threats against the firm's systems using a "Detection-as-Code" philosophy.
  • Incident Response: Respond to and mitigate active incidents and alerts within our security monitoring systems.
  • Threat Hunting: Proactively hunt for sophisticated adversaries targeting our infrastructure by analyzing logging and telemetry.
  • Intelligence Action: Process and action threat intelligence reports, converting attacker TTPs into actionable detections across various tools and languages.
  • Automation & Coding: Contribute to the firm’s Python-based ecosystem to automate analysis processes and increase detection accuracy.
  • Business Collaboration: Work with various business units to gain a deep understanding of internal networks to better inform hunting and risk-modeling strategies.
  • Telemetry Analysis: Review and analyze packet captures, media, and network device logs to support risk and detection capabilities.

Qualifications

  • Education: Bachelor’s degree in Computer Science, Computer Engineering, or a related technical field.
  • Programming: Strong proficiency in Python is mandatory for contributing to our D&R codebase.
  • Data Analysis: Experience conducting deep-dive analysis of media, packet captures, and logs. Familiarity with Pandas and Jupyter Notebooks for threat hunting is highly desirable.
  • Technical Breadth: Experience with modern SIEM platforms (Google SecOps preferred) and a variety of 3rd party endpoint, network, and cloud security tools.
  • Communication: Strong interpersonal skills with the ability to communicate complex technical threats to both technical and non-technical stakeholders.
  • Availability: Ability to work a weekend-based schedule (local daytime hours) with flexibility during the week (2 days).

Benefits

  • Competitive compensation package commensurate with experience.
  • Comprehensive health, dental, and vision insurance.
  • Opportunities for continuous professional development and training.
  • A collaborative and challenging work environment with state-of-the-art technology.

Job Requirements

  • Education: Bachelor’s degree in Computer Science, Computer Engineering, or a related technical field.
  • Programming: Strong proficiency in Python is mandatory for contributing to our D&R codebase.
  • Data Analysis: Experience conducting deep-dive analysis of media, packet captures, and logs. Familiarity with Pandas and Jupyter Notebooks for threat hunting is highly desirable.
  • Technical Breadth: Experience with modern SIEM platforms (Google SecOps preferred) and a variety of 3rd party endpoint, network, and cloud security tools.
  • Communication: Strong interpersonal skills with the ability to communicate complex technical threats to both technical and non-technical stakeholders.
  • Availability: Ability to work a weekend-based schedule (local daytime hours) with flexibility during the week (2 days).

Benefits

  • Competitive compensation package commensurate with experience.
  • Comprehensive health, dental, and vision insurance.
  • Opportunities for continuous professional development and training.
  • A collaborative and challenging work environment with state-of-the-art technology.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001

The Senior IT Application Security Engineer will act as a subject matter expert, guiding software development teams in designing and implementing secure solutions by enforcing security checks throughout the SDLC. This role involves leading application security initiatives, defining standards, mentoring team members, and advancing the overall maturity of the application security program.

Application SecurityThreat ModelingSecure CodingOWASP Top 10SDLCCISSPPenetration TestingRisk AssessmentC#JavaC++AgileScrumSAFeCloud SecurityContainerizationMicroservicesCI/CD
United States
$120K - $191K / year
Security Engineer4 days ago
Full TimeRemoteTeam 10,001

The Application Security Engineer assists development teams in creating secure solutions by enforcing security checks throughout the SDLC, defining application security standards, and providing curated security training content. Key duties include presenting on security topics, facilitating penetration tests, triaging findings, and offering tailored remediation guidance to developers.

Application SecurityThreat ModelingSecure CodingOWASP Top 10Penetration TestingRisk AssessmentC#JavaCISSP
United States
$100K - $156K / year
Full TimeRemoteTeam 1,001-5,000Since 1977H1B No Sponsor

IT Professional III ensuring security and privacy for NLR's information systems

CloudCyber SecurityFirewalls
Colorado
$83.6K - $150.5K / year

Senior Cloud Cybersecurity Engineer

Tanium

Tanium delivers Autonomous Endpoint Management (AEM) with the industry’s only true real-time platform for AI.

Security Engineer4 days ago
Full TimeRemoteTeam 1,001-5,000Since 2007H1B Sponsor

Senior Cloud Cybersecurity Engineer collaborating with teams to defend Tanium Cloud services

AWSAzureCloudKubernetesLinuxSQL
United States
$120K - $355K / year