Threat Detection Engineer
You will build and operate threat-detection and automation capabilities. You will create SIEM parsers and alert rules, analyze logs, tune detections, automate response workflows, and hunt for threats across cloud, application, and endpoint environments. You will improve detection quality and uptime through testing and health monitoring, enhance internal tools, lead complex incident investigations, collaborate on detection rules, and support the incident-response on-call rotation.
Responsibilities
- Support the development and implementation of a strategic vision for threat detection
- Create custom SIEM log parsers and configure alert rules
- Perform log analysis and tune detections to reduce false positives
- Build security automations and services for data enrichment and phishing-email removal
- Hunt for sophisticated threats across infrastructure
- Monitor and respond to threats across AWS, GCP, internal applications, and Windows and macOS endpoints
- Develop and implement business-specific threat-detection rules with cross-functional teams
- Ensure detection quality and ecosystem uptime through test-driven development and health monitoring
- Build and enhance internal tools for threat detection and response
- Lead complex incident investigations and coordinate containment, remediation, and recovery
- Support the security incident-response on-call rotation
Requirements
- Knowledge of Splunk, Scanner, Sentinel, or SecOps
- Understanding of attack and defence techniques for cloud, SaaS, and desktop environments
- Experience in security automation, scripting, and end-to-end automated workflows
- Familiarity with SOAR platforms and automated threat detection and response
- Spoken and written communication skills
Benefits
- Remote-first work
- 25 days of paid annual leave
- 3 additional days for volunteering and learning
- Private health insurance
- Mental health support platform
- FitPass
- Family and friendly leave according to statutory requirements
- Share options