Engineer III - Information Security
Core
Engineer owning the end-to-end path from raw log source to validated security detection, bridging data pipeline and detection content.
Role type
Senior IC security data pipeline and detection engineer
Builds
Centralized logging pipeline, SIEM integrations, and high-fidelity detection rules/alerts
Domain
Cybersecurity, Security Operations Center (SOC), Log Management
Deliverable
production ML models | product features
Required skills
Splunk engineering (onboarding, parsing, SPL), log pipeline platforms (Databahn, Cribl), detection engineering (static/dynamic rules), MITRE ATT&CK mapping, Python scripting, UEBA/behavioral analytics, detection-as-code (Sigma, CI/CD)
Preferred skills
UEBA-driven analytics, detection validation/purple-team exercises, M&A log-source integration, compliance dashboarding, ReliaQuest GreyMatter
Technologies
Splunk, Databahn, Cribl, MITRE ATT&CK, Python, Sigma, ReliaQuest GreyMatter
Responsibilities
Onboard and normalize log sources (endpoints, cloud, SaaS) into the centralized pipeline; build and tune detection rules for malicious and anomalous activity; maintain detection coverage maps against MITRE ATT&CK; support on-call rotation for pipeline and detection platform issues
Seniority
Senior, hands-on IC