Senior Cybersecurity Engineer (UCF)
Envision Employment Solutions is currently looking for a Senior Cybersecurity Engineer (UCF) for one of our partners, a global leader in consulting, digital transformation, technology and engineering services!
About:
We are seeking an experienced Senior Cybersecurity Engineer (UCF) to join our team and play a key role in strengthening our threat detection capabilities. In this role, you will design, develop, and optimize detection content that enables the Security Operations Center (SOC) to identify and respond to evolving cyber threats. Working closely with Threat Intelligence, Threat Hunting, and SOC teams, you will build and maintain high-quality detection rules, enhance detection coverage, and continuously improve the accuracy and effectiveness of security monitoring across the organization.
Responsibilities:
Detection Engineering
- Design, develop, and maintain detection rules, signatures, and playbooks.
- Build, test, deploy, and optimize detection logic within the Use Case Factory (UCF).
- Validate detection capabilities against emerging threats and attack techniques.
- Continuously tune detection content to improve accuracy and reduce false positives.
Security Operations
- Deploy and maintain detection capabilities across the organization's SOC infrastructure.
- Analyze and correlate security events from multiple data sources.
- Support the identification and investigation of suspicious or malicious activities.
- Collaborate with SOC teams to improve detection coverage and operational effectiveness.
Documentation & Continuous Improvement
- Maintain technical documentation for detection rules, processes, and operational procedures.
- Support continuous improvement initiatives by identifying gaps and recommending enhancements.
- Stay informed on emerging threats, attacker techniques, and detection best practices.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (preferred)
- Minimum 6-10 years of experience in cybersecurity operations, detection engineering, or SOC environments
- Proven experience in developing and managing detection rules within SIEM platforms (e.g., Splunk)
- In-depth understanding of cybersecurity technologies, threat detection methodologies, and security operations
- Excellent communication, interpersonal, and problem-solving skills
- Fluency in written and spoken English
- Strong analytical and reporting skills
- Proficiency in various security tools and technologies, including SIEM (Splunk), SOAR platforms, scripting languages (Python, PowerShell, Bash), and CI/CD pipelines
As published by workable
First name, Last name, Email, Headline, Phone, Address, Photo, Education, Experience, Summary, Resume, Cover letter
- How did you hear about us? choose one
- If you were approached by a recruiter, what is the name of the recruiter? written answer
- Kindly list your current responsibilities. written answer
- What techniques do you use to improve detection accuracy? written answer
- What types of security events do you commonly investigate? written answer
- How do Threat Intelligence and Detection Engineering complement each other? written answer
- How have you used Python, PowerShell, or Bash in your previous roles? written answer
- How do you approach troubleshooting ineffective or noisy detection rules? written answer
- What metrics do you use to evaluate detection effectiveness? written answer
- What is your current compensation? and in which currency? written answer
- What are your compensation expectations? written answer
- When can you start? (Notice Period) written answer