SoftServe
SoftServe
New

Security Detection Engineer

Brak informacji o wynagrodzeniu
MidFull-time
#413879·Dodano wczoraj·0
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

NetworkingNetwork SecurityTCPDNSHTTPTLSData analysisPythonSuricataAISecurityCommunication skills

Wymagania

  • Proven experience developing code-like detection content for network threats, including rule-based, signature-based, or behavioral detections
  • Strong knowledge of networking and network security, including TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectors
  • Coding or scripting proficiency for detection development and data analysis, especially with Python and SQL
  • Experience with rule languages or detection formats such as Sigma, Snort, Suricata, or similar
  • Practical experience applying AI/ML techniques to security detection, including anomaly detection, classification, or behavioral modeling
  • Experience with SecOps workflows, including threat hunting, incident investigation support, and improving detections based on operational findings
  • Experience using threat intelligence tools, feeds, and OSINT sources to enrich and contextualize detection logic
  • Familiarity with detection frameworks such as MITRE ATT&CK and mapping detections to adversary tactics and techniques
  • Experience with NDR platforms, security analytics, or SIEM solutions
  • Strong analytical and problem-solving skills, with high attention to detail
  • Clear documentation and cross-team communication skills
  • Endpoint security experience is a strong plus, but not mandatory

Obowiązki

  • Design and build behavioral models to detect malicious activity and identify meaningful anomalies in network behavior
  • Develop detections for attack techniques such as beaconing, DGA, data staging, lateral movement, DNS tunneling, scanning, port hopping, and unusual remote administration activity
  • Translate concrete detection use cases into production-ready detection logic, signatures, and behavioral indicators
  • Collaborate with threat intelligence teams, including Cisco Talos, to convert emerging threat research into actionable detection content
  • Build, evaluate, and continuously tune detections using efficacy metrics such as precision, recall, false-positive rate, and MITRE ATT&CK coverage
  • Use production-scale telemetry on Databricks to validate and improve detection performance
  • Work with engineering teams to productionize detections as part of a SaaS service, with potential deployment to on-premise environments
  • Support threat hunting, investigations, and triage activities with detection expertise
  • Use threat intelligence platforms and OSINT sources to enrich detections with current threat context, reputation data, and IOCs
  • Apply networking and network security knowledge to model traffic behavior and create precise, low-noise detection logic
  • Document detection methodology, assumptions, tuning decisions, and share knowledge across security and engineering teams

Inne informacje

SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.

SoftServe

SoftServe

30 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz