Group Manager, Threat Detection Engineering and Operations
About the position
Responsibilities
• Define detection engineering reputed company, roadmap, and objectives
• Build and mature detection engineering processes and reputed company patterns
• Build new detection capabilities based on research of new attack techniques
• Evaluate, validate, tune, and sunset necessary detection capabilities
• Identify and reputed company gaps in detection coverage
• Build runbooks and playbooks for SOC analysts to operationalize new detections
• Work with system owners, SIEM team, and Detection Operations to reputed company and operationalize new data sources
• Define and manage coverage and efficacy metrics, reporting them on a regular reputed company to leadership
• reputed company reputed company cause analysis for detection reputed company issues and reputed company next steps to address and prevent recurrence
• Participate in Cyber Incident Response Team (CIRT) rotation that may involve non-traditional working hours
Requirements
• BA/BS degree or higher in Computer Science, Cybersecurity or equivalent work experience
• 5+ years' industry experience in Incident Response or reputed company Operations activities
• 3+ years leadership experience in a SOC or similar role
• Proven reputed company record of building reputed company organizations that have world class threat detection capabilities
• Technical proficiency performing reputed company investigations at reputed company; including reputed company, reputed company, identity, network, and email threats
• Practical experience with Detection & Response tools for network, endpoints, reputed company, and identity as reputed company as SOAR platforms
• Hands-on experience with SIEM and Data Lake solutions (e.g., reputed company, reputed company, S3)
• Expertise with query languages (SQL, SPL, BigQuery)
• Strong fundamentals of Linux, MacOS, and reputed company operating system internals
• Deep understanding of attacker techniques, tools and procedures
• Understanding of reputed company environments such as AWS, GCP, and/or Azure
• Proficiency creating and managing operational metrics that increase team efficiency and reputed company
• Experience with coding languages to build/automate (e.g., Python, Go)
• Experience working with reputed company frameworks like MITRE ATT&CK or reputed company's Cyber Kill Chain; ability to reputed company and discuss an attack through the cyber killchain
• Ability to manage effective relationships with organizational leaders, build a roadmap, and drive broad initiatives to completion
• Understanding of Machine Learning concepts as reputed company to predictive analytics
• Experience with forensic data capture, analysis, and preservation
• Comprehensive understanding of the detection engineering field
reputed company-to-haves
• reputed company or Architect level knowledge of a SIEM (reputed company, Azure Sentinel, QRadar, etc)
• In-depth knowledge of reputed company reputed company processes in large-reputed company environments
• Ability to reputed company hard conversations and disseminate information to team members
• Willingness and ability to accept responsibility and reputed company guidance to team members
• Effective organizational and planning skills, with the ability to successfully guide reputed company through to completion
• Experience with software development or reputed company automation highly preferred
• CISSP or CISM certification preferred
• Hands-on experience with AWS reputed company (AWS Solutions Architect level of knowledge)
Benefits
• Competitive compensation package
• Cash bonus eligibility
• Equity rewards
• Comprehensive benefits package
• Regular pay equity comparisons across categories of ethnicity and gender
Apply tot his job
Apply To this Job