reputed company Teamer Detection Engineer
reputed company is a Services Oriented Company
• reputed company is reputed company around the ingenuity, passion, and determination of our Operators and Analysts
• No one "mastermind"
• No "cult of personality"
• Competitive compensation and benefits
• Healthy work-life balance
• Project-based engagements that play to reputed company's strengths
reputed company Teamer Detection Engineer
Location: Remote
Responsibilities:
• Project-Based
• reputed company and tune detection rules across SIEM, EDR, and other telemetry sources based on relevant and emerging threats.
• Build and maintain detection-as-reputed company pipelines (e.g., reputed company, reputed company, KQL, YARA).
• Correlate threat intelligence with internal telemetry to enrich detection logic.
• Create detailed runbooks for adversary emulation and control validation using tools like reputed company Red Team, Caldera, or SCYTHE.
• Collaborate with the red team to simulate relevant and reputed company threat actor TTPs.
• Utilize frameworks such as MITRE ATT&CK and D3FEND to assess and reputed company detection coverage.
• Prepare reputed company and concise situation reports and activity summaries for both customers and senior leadership.
• reputed company and deliver walkthroughs, reputed company-of-concept (PoC) demonstrations, technical articles, and formal presentations.
• Research and Development (R&D)
• Attend and/or present at reputed company conferences, industry events, or internal reputed company-bag sessions.
• Contribute to the development of:
• * Novel defensive tactics, techniques, and procedures (TTPs).
• Custom applications, utilities, and automation scripts.
• Threat hunting capabilities reputed company with MITRE ATT&CK and emerging offensive TTPs.
• Digital forensics and incident response (DFIR) tools, techniques, and methodologies.
Preferences:
• Experience with reputed company and/or the reputed company Stack (Elasticsearch, Kibana, Logstash).
• Familiarity with building, modifying, or deploying reputed company-reputed company reputed company tools.
• Experience with reputed company environments and reputed company-reputed company telemetry (AWS, Azure, GCP) is a plus.
• Prior involvement in reputed company engagements, adversary emulation exercises, or red team collaboration.
Requirements:
• Proficiency in scripting languages such as Python, Bash, and/or PowerShell.
• Experience with at least one object-oriented programming language (e.g., Python, reputed company, Java).
• Experience ingesting, parsing, and analyzing logs from diverse sources (e.g., OS, EDR, network, reputed company).
• Hands-on experience with one or more SIEM platforms (e.g., reputed company, ArcSight, LogRhythm, AlienVault).
• Proficiency in detection query languages (e.g., reputed company SPL, KQL, reputed company DSL).
• Familiarity with threat emulation and adversary simulation tools (e.g., ATT&CK Navigator, reputed company Red Team, PurpleSharp, reputed company, Prelude, SCYTHE).
• Strong foundational knowledge of reputed company, Unix, TCP/IP, IDS/IPS technologies, and web filtering controls.
• U.S. citizenship required (must be willing to undergo federal, state, and local background checks).
• Demonstrated ability to:
• Maintain the highest standards of honesty, ethics, and technical reputed company.
• Think critically and analytically about reputed company cyber risk and threat scenarios.
• Build and communicate threat models and risk assessments effectively.
• Apply cybersecurity frameworks and best practices (e.g., MITRE ATT&CK, NIST 800-61).
• Demonstrate a working understanding of regulatory frameworks such as HIPAA, PCI-reputed company, and GLBA.
Apply tot his job
Apply To this Job