Detection Engineer developing threat detection capabilities and collaborating with threat team for innovative security solutions. Working in hybrid environment at Our Future Health.
Responsibilities
Developing new threat-led detections in collaboration with our threat team based on both threat intelligence and the results of threat hunts.
Creating novel analytic methods and techniques for incident detection.
Working with our MSP provided SOC to maintain our detection catalogue and tune existing rules.
Developing and tuning Data Loss Prevention, Insider Risk Management and other types of security rules within Microsoft Purview and other key security monitoring tools.
Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided, detections and other types of engineering work are delivered to the appropriate standard and that the maturity (inc. efficiency) of our security monitoring is continually improving.
Supporting the development of automated custom reports on security operational performance and broader security topics (using Sentinel workbooks).
Collaborating with wider tech and security teams on the appropriate security monitoring for our various systems, including cloud platforms, SaaS applications and inhouse developed systems.
Documenting security processes and security tool low-level design/configuration.
Contributing to the development of security service delivery and operation documentation.
Supporting the security engineers, threat analysts and wider security team with their various responsibilities, including achieving and maintaining ISO 27001 certification and anything that involves KQL.
Requirements
Highly proficient in writing KQL and ideally some level of proficiency in Python and Terraform.
Significant hands-on experience with Microsoft Sentinel.
Experience with Microsoft’s Defender suite, in particular Defender for Endpoints and Defender for O365.
Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities.
Experience with Microsoft Purview tooling, in particular MPIP and Purview Data Loss Prevention.
Experience with cloud-native logging (in particular Azure and Kubernetes).
Experience of an ‘everything-as-code’, or at least a ‘detection-as-code’ approach, including CI/CD pipelines.
Exposure to working with/inside an MSP SOC.
Exposure to Agile working.
Knowledge of attacker Tactics, Techniques and Procedures (TTPs).
Knowledge of statistics, data science and AI/ML, in particular when applied to cyber security.
MineStar Performance Engineer developing next generation performance simulators for mining operations. Collaborating with engineering and operational teams to improve performance insights and tool enhancements.
Engineer maintaining mechanical and electrical machinery at Coveris in Gainsborough, ensuring maximum machine availability and adherence to health and safety policies.
Intern role at Micron focused on developing smart scheduling systems for manufacturing. Collaborating with teams to optimize processes and improve efficiency in operations.
Process Engineer responsible for continuous improvement in Material Handling at Nucor. Leading quality improvement, analyzing equipment, and collaborating with teams in Kentucky.
Associate Engineer providing in - person technology support for Kmart and Target team members. Collaborating with technical staff and resolving hardware/software issues in a face - to - face environment.
Technical Support Engineer in microelectronics at Thales. Providing support and coaching for repair technicians and managing technical operations in Etrelles, France.
Senior Fire Protection Engineer leading design efforts for fire systems in various U.S. locations. Collaborating with teams to deliver compliant fire protection solutions while mentoring junior staff.
Senior Bridge Engineer at LEA leading design and rehabilitation of transportation structures. Overseeing project teams and ensuring compliance with safety, quality, and budget standards.
E - Ingenieur für MSR - Technik bei ROM Technik in Stuttgart. Erstellung von Regelschemen und Unterstützung der Projektleiter im Bereich Gebäudeautomation.
NPI Engineer facilitating product launches across critical sites with the Plexus TED Program. Collaborating with customer - focused teams to enhance solutions and drive operational excellence.