Engineer, Threat Detection - 5
Core
Building a robust detection and automation platform to protect the company by proactively hacking internal systems, monitoring infrastructure, and responding to emerging threats.
Role type
Senior Threat Detection Engineer (Security Operations)
Builds
Automated threat detection and response services, custom log parsers, and security automation workflows.
Domain
Cybersecurity, Cloud Security (AWS, GCP), Endpoint Security
Deliverable
production ML models | infrastructure
Required skills
SIEM (Splunk, Scanner, Sentinel, SecOps), Cloud security (AWS, GCP), SaaS security (Google Workspace, Okta), Endpoint security (Windows, macOS), Security automation scripting, Threat hunting, Log analysis, Incident investigation, Test-driven development
Preferred skills
SOAR platforms, Repository of automation scripts
Technologies
Splunk, Scanner, Sentinel, SecOps, AWS, GCP, Google Workspace, Okta, Windows, macOS
Responsibilities
Create custom log-parsers and configure alert rules for SIEM systems; Build security automations to handle data enrichment and phishing removal; Hunt for sophisticated threats across infrastructure and endpoints; Collaborate on business-specific threat detection rules; Ensure detection quality and uptime via test-driven development; Lead complex incident investigations and coordinate cross-functional response; Participate in security incident response on-call rota.
Seniority
Senior, hands-on IC