Threat Detection Engineer

Remote, USA Full-time
Job TitleThreat Detection EngineerRelevant Experience(in Yrs)Technical/Functional SkillsELK stack, Fireeye HX, Sysmon, WinlogbeatExperience RequiredRoles & ResponsibilitiesTechnical knowledge to write & develop rules for CIRT analysis, experience on ELK stack, Fireeye HX, Sysmon, Winlogbeat, bolthires-CD pipeline. • Deep understanding of cyber threat actor attacker techniques and tools (such as malware, common attack types) including evasion techniques, reconnaissance, scanning, exploitation, evasion, lateral movement, persistence, and exploits), proficient with MITRE ATT&CK• Deep understanding of security operations center processes, tools, and data for analysis & control mitigations, security event timeline analysis and baselining with experience in the analysis of logs and data for the development and implementation of custom detections to counter attacker techniques, known vulnerabilities and evasion methods• Security architecture (network topology, firewalls, proxies, web content filtering, wireless, EDR, IDS, IPS, SIEM, SOAR, etc.)• Network data sources (full packet analysis, flow data, dns logs, proxy logs, NIDS, etc.)• Knowledge and experience with common scripting languages and tools Python, PowerShell, Bash, YAML• Deep knowledge of compound logical operations (AND, OR, NOT), regular expressions• Experience extracting data from logs, SQL, and APIs• Knowledge and experience with tools used to build threat detections (Elastalert, Logstash, Kibana (ELK), Fireeye HX, Sysmon, Winlogbeat, Linux Auditd)• Deep understanding and experience with Operating Systems Including: Administration, configuration, registry, processes (Windows, Mac, and Linux)• Experience in red team/blue team/incident responder interactions• Understanding of bolthires/CD pipelines• Experience with source control tools (GitGeneric Managerial SkillsGood Communication, Team coordination and Status update to customersEducationB.TechStart date (dd-mmm-yy)04-MAY-23Duration of assignment (in Months)3 to 6 MonthsWork Location (State, City and Zip)Remote, San Antonio,TXBase salary range120-125kKey words to search in resumeDevelop Use cases for Threats, Python, Bash scriptingPrescreening QuestionnaireDo you have experience in (Elastalert, Logstash, Kibana (ELK) & Develop Use cases for Threats Apply tot his job
Apply Now
Back to Home