Padmi

Threat Detection Engineer

IndiaPosted 2 months ago
CybersecurityMid-levelFull Time; Regular
Apply at Sapphire Software Solutions

Opens the source posting on shine.com

Source description

About the role

View original

Role Overview: You are seeking a remote Detection Engineer position with a global consulting firm. As the first Detection Engineer in the team, your role involves building advanced detections and contributing to the technical foundation of a continuous monitoring & detection program. You will work within the Security Operations team and play a crucial role in enhancing the organization's security posture. Key Responsibilities: - Possessing 5+ years of hands-on detection engineering experience, including writing production detection rules and understanding correlation. - Demonstrating MITRE ATT&CK fluency and the ability to map red team findings to detection gaps. - Having knowledge of SPL to write effective Splunk searches and discern what makes a rule expensive or fragile. - Utilizing experience with at least one EDR platform at a detection level, such as CrowdStrike Falcon or Microsoft Defender for Endpoint. - Understanding offensive security techniques and attacks at a technique level. - Validating detections through atomic testing, purple team participation, or equivalent empirical validation methods. - Working with incomplete data to make coverage decisions and document the reasoning. Qualifications Required: - Purple team experience or running exercises end-to-end. - Sigma rule authoring skills for vendor-agnostic detection development and rule translation. - Ability to integrate threat intelligence into detection requirements. - Understanding of risk-based alerting to score and prioritize alerts effectively. - Possessing offensive security background or certifications like OSCP, CRTE, or similar. - Experience with CrowdStrike Falcon detection authoring and familiarity with MITRE ATLAS for AI/ML threat scenarios. - Proficiency in scripting with Python for detection automation, log parsing, or tooling integrations. - Skilled in writing or reviewing logging standards, detection standards, or security governance documentation. Additional Company Details (if applicable): You will be working in an ambiguous, large-scale environment with numerous unknowns. Your responsibility includes translating offensive security findings into actionable detections, auditing existing detections in Splunk, closing coverage gaps, and establishing governance for a measurable and defensible program. Your role is critical in contributing to the organization's security posture. Role Overview: You are seeking a remote Detection Engineer position with a global consulting firm. As the first Detection Engineer in the team, your role involves building advanced detections and contributing to the technical foundation of a continuous monitoring & detection program. You will work within the Security Operations team and play a crucial role in enhancing the organization's security posture. Key Responsibilities: - Possessing 5+ years of hands-on detection engineering experience, including writing production detection rules and understanding correlation. - Demonstrating MITRE ATT&CK fluency and the ability to map red team findings to detection gaps. - Having knowledge of SPL to write effective Splunk searches and discern what makes a rule expensive or fragile. - Utilizing experience with at least one EDR platform at a detection level, such as CrowdStrike Falcon or Microsoft Defender for Endpoint. - Understanding offensive security techniques and attacks at a technique level. - Validating detections through atomic testing, purple team participation, or equivalent empirical validation methods. - Working with incomplete data to make coverage decisions and document the reasoning. Qualifications Required: - Purple team experience or running exercises end-to-end. - Sigma rule authoring skills for vendor-agnostic detection development and rule translation. - Ability to integrate threat intelligence into detection requirements. - Understanding of risk-based alerting to score and prioritize alerts effectively. - Possessing offensive security background or certifications like OSCP, CRTE, or similar. - Experience with CrowdStrike Falcon detection authoring and familiarity with MITRE ATLAS for AI/ML threat scenarios. - Proficiency in scripting with Python for detection automation, log parsing, or tooling integrations. - Skilled in writing or reviewing logging standards, detection standards, or security governance documentation. Additional Company Details (if applicable): You will be working in an ambiguous, large-scale environment with numerous unknowns. Your responsibility includes translating offensive security findings into actionable detections, auditing existing detections in Splunk, closing coverage gaps, and establishing governance for a measurable and defensible program. Your role is critical in contributing to the organization's security posture.

One address, no account. We’ll tell you when matching roles go live.

More at Sapphire Software Solutions

Related open roles

View all roles