Detection Engineer
Core
Monitoring and analyzing security logs to detect threats, verify findings, and maintain cloud infrastructure for a student loan servicer and cybersecurity operations team.
Role type
Cybersecurity Log Operations Engineer
Builds
Cloud infrastructure and security monitoring pipelines for on-premise and cloud-based elements
Domain
Cybersecurity / Cloud Infrastructure / Student Loan Services
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM tools, log aggregators, cloud infrastructure (AWS/Azure/GCP), threat verification, logging source configuration, data transformation, change control, audit documentation, PowerShell, Python, BASH, Chef, Ansible
Preferred skills
SOAR, database monitoring, threat detection mechanisms, alarming mechanisms, operational logging, Splunk, Google SecOps, Google Cloud Observability, Cribl, Bindplane, Datadog, Sysmon, Syslog, Windows Event logs, Linux Redhat, Jira, Confluence, ServiceNow
Technologies
AWS, Azure, Google Cloud, Google Observability, Cribl, Splunk, Datadog, Sysmon, Syslog, Jira, Confluence, ServiceNow, Chef, Ansible
Responsibilities
Monitor and work with logs in SIEM tools and log aggregators; verify threat findings; build and maintain cloud infrastructure; set up logging sources and data transformations; participate in change control and IT governance; stay updated on threat landscape; respond to audit findings; develop security system documentation
Seniority
Mid-level, hands-on IC