Security Engineer
Full-time
Not Applicable
Job Overview
Job description
Job Description
Reporting to the Manager of Threat Detection Engineering, the Security Engineer will work with our teams, including cyber threat intelligence analysts, SOC analysts, threat detection engineers, server and network administrators, security tool administrators, and department customers. You will have information security experience in incident response and understanding of security log feeds mapping the data into the SIEM.
You will:
- Understand data feeds of multiple security tools and logs that feed the SIEM & UEBA technologies. Identify capabilities and quality of these feeds and recommend improvements
- Create new content use cases based on threat intelligence, analyst feedback, available log data, and previous incidents
- Perform daily activities of the content life cycle, including creating new use cases, testing content; tuning, and removing content; and maintain associated documentation
- Improve vulnerabilities in the different application environments
- Work with the other security teams and product SMEs to identify gaps within the existing capability
- Develop parsers/field extractions to facilitate reliable content development
- Develop custom scripts to enhance default SIEM functionality
- Participate in root cause analysis on security incidents and provide recommendations for new data sources and enrichment
Qualifications
Qualifications:
- 5+ years experience in security engineering or site reliability engineering
- Excellent Terraform skills required and experience with Cloud Migration
- Experience working with and developing CI/CD pipelines for Infrastructure as Code required
- Knowledge of programming/scripting fundamentals (python/golang) required
- Expertise in performing ETL onboarding for diverse log feed technologies required
- Experience supporting a Splunk platform administration, new content dashboards, applications, and use cases
- Hands-on experience developing Rest API's to capture data from external sources
- Experience with Agile methodologies
- Understanding of multiple log formats and source data for SIEM Analysis
- Solid background with Windows and Linux platforms (security or system administration)