Network Security Service Engineer
Core
Proactively identify and investigate security issues, implement automation for network security controls, and respond to intrusions and escalations to limit system exposure.
Role type
Senior IC network security service engineer (detection engineering & incident response)
Builds
Detections, response runbooks, and automation playbooks for Azure Sentinel and partner XDR signals
Domain
Cyber security, threat analytics, and security operations (SOC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
threat modeling, anomaly detection, SIEM administration, incident response, detection engineering, automation development, security policy implementation, metrics analysis, intrusion analysis, MITRE ATT&CK mapping
Preferred skills
SOAR playbook development, false-positive reduction, blameless postmortem facilitation, detection-as-code workflow implementation
Technologies
Azure Sentinel, MITRE ATT&CK, SOAR, XDR
Responsibilities
Build and tune detections using detection-as-code workflows; map coverage to MITRE ATT&CK framework; author and maintain TSGs and response runbooks; partner with SOC during P0/P1 incidents; contribute to blameless postmortems; drive automation playbooks to reduce analyst toil; analyze attempted or successful security compromises; respond to escalations and recommend improvements; participate in on-call rotation for security services
Seniority
Senior, hands-on IC