Detection Engineer
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build and maintain security detection and incident response capabilities, triage alerts, investigate incidents, develop and tune detection rules, monitor endpoints and cloud environments, automate response tasks, and translate attack techniques and threat intelligence into actionable detections.
Requirements
- Incident response and security operations experience
- Detection engineering experience
- Google SecOps and Chronicle experience
- SIEM infrastructure experience
- JAMF MDM experience
- Google Workspace and Okta monitoring experience
- Google Cloud security monitoring experience
- Python or Bash scripting skills
- Knowledge of attack techniques and threat intelligence
- MITRE ATT&CK and NIST Cybersecurity Framework familiarity
- Analytical and problem-solving skills
Responsibilities
- Triage security alerts
- Conduct security investigations
- Lead incident response efforts
- Develop, tune, and maintain security detection rules and alerts
- Onboard and parse SIEM data
- Create SIEM rules and dashboards
- Monitor macOS endpoints and SaaS applications
- Monitor Google Cloud security
- Automate detection and response tasks
- Parse security data
- Integrate security tooling
- Translate attack techniques into actionable detections
Benefits
- Annual discretionary professional development stipend
- Annual discretionary stipend for meeting colleagues
- Annual company offsite
- Monthly co-working stipend
