Source description
About the role
Role Overview: You are seeking a remote Detection Engineer position with a global consulting firm. As the first Detection Engineer in the team, your role involves building advanced detections and contributing to the technical foundation of a continuous monitoring & detection program. You will work within the Security Operations team and play a crucial role in enhancing the organization's security posture. Key Responsibilities: - Possessing 5+ years of hands-on detection engineering experience, including writing production detection rules and understanding correlation. - Demonstrating MITRE ATT&CK fluency and the ability to map red team findings to detection gaps. - Having knowledge of SPL to write effective Splunk searches and discern what makes a rule expensive or fragile. - Utilizing experience with at least one EDR platform at a detection level, such as CrowdStrike Falcon or Microsoft Defender for Endpoint. - Understanding offensive security techniques and attacks at a technique level. - Validating detections through atomic testing, purple team participation, or equivalent empirical validation methods. - Working with incomplete data to make coverage decisions and document the reasoning. Qualifications Required: - Purple team experience or running exercises end-to-end. - Sigma rule authoring skills for vendor-agnostic detection development and rule translation. - Ability to integrate threat intelligence into detection requirements. - Understanding of risk-based alerting to score and prioritize alerts effectively. - Possessing offensive security background or certifications like OSCP, CRTE, or similar. - Experience with CrowdStrike Falcon detection authoring and familiarity with MITRE ATLAS for AI/ML threat scenarios. - Proficiency in scripting with Python for detection automation, log parsing, or tooling integrations. - Skilled in writing or reviewing logging standards, detection standards, or security governance documentation. Additional Company Details (if applicable): You will be working in an ambiguous, large-scale environment with numerous unknowns. Your responsibility includes translating offensive security findings into actionable detections, auditing existing detections in Splunk, closing coverage gaps, and establishing governance for a measurable and defensible program. Your role is critical in contributing to the organization's security posture. Role Overview: You are seeking a remote Detection Engineer position with a global consulting firm. As the first Detection Engineer in the team, your role involves building advanced detections and contributing to the technical foundation of a continuous monitoring & detection program. You will work within the Security Operations team and play a crucial role in enhancing the organization's security posture. Key Responsibilities: - Possessing 5+ years of hands-on detection engineering experience, including writing production detection rules and understanding correlation. - Demonstrating MITRE ATT&CK fluency and the ability to map red team findings to detection gaps. - Having knowledge of SPL to write effective Splunk searches and discern what makes a rule expensive or fragile. - Utilizing experience with at least one EDR platform at a detection level, such as CrowdStrike Falcon or Microsoft Defender for Endpoint. - Understanding offensive security techniques and attacks at a technique level. - Validating detections through atomic testing, purple team participation, or equivalent empirical validation methods. - Working with incomplete data to make coverage decisions and document the reasoning. Qualifications Required: - Purple team experience or running exercises end-to-end. - Sigma rule authoring skills for vendor-agnostic detection development and rule translation. - Ability to integrate threat intelligence into detection requirements. - Understanding of risk-based alerting to score and prioritize alerts effectively. - Possessing offensive security background or certifications like OSCP, CRTE, or similar. - Experience with CrowdStrike Falcon detection authoring and familiarity with MITRE ATLAS for AI/ML threat scenarios. - Proficiency in scripting with Python for detection automation, log parsing, or tooling integrations. - Skilled in writing or reviewing logging standards, detection standards, or security governance documentation. Additional Company Details (if applicable): You will be working in an ambiguous, large-scale environment with numerous unknowns. Your responsibility includes translating offensive security findings into actionable detections, auditing existing detections in Splunk, closing coverage gaps, and establishing governance for a measurable and defensible program. Your role is critical in contributing to the organization's security posture.
More at Sapphire Software Solutions