Detection Engineer developing threat detection capabilities and collaborating with threat team for innovative security solutions. Working in hybrid environment at Our Future Health.
Responsibilities
Developing new threat-led detections in collaboration with our threat team based on both threat intelligence and the results of threat hunts.
Creating novel analytic methods and techniques for incident detection.
Working with our MSP provided SOC to maintain our detection catalogue and tune existing rules.
Developing and tuning Data Loss Prevention, Insider Risk Management and other types of security rules within Microsoft Purview and other key security monitoring tools.
Alongside our Head of Cyber Defence, supervising the MSP SOC to ensure a high-quality service is provided, detections and other types of engineering work are delivered to the appropriate standard and that the maturity (inc. efficiency) of our security monitoring is continually improving.
Supporting the development of automated custom reports on security operational performance and broader security topics (using Sentinel workbooks).
Collaborating with wider tech and security teams on the appropriate security monitoring for our various systems, including cloud platforms, SaaS applications and inhouse developed systems.
Documenting security processes and security tool low-level design/configuration.
Contributing to the development of security service delivery and operation documentation.
Supporting the security engineers, threat analysts and wider security team with their various responsibilities, including achieving and maintaining ISO 27001 certification and anything that involves KQL.
Requirements
Highly proficient in writing KQL and ideally some level of proficiency in Python and Terraform.
Significant hands-on experience with Microsoft Sentinel.
Experience with Microsoft’s Defender suite, in particular Defender for Endpoints and Defender for O365.
Experience with Microsoft Entra ID (previously AAD), including the Identity Governance capabilities.
Experience with Microsoft Purview tooling, in particular MPIP and Purview Data Loss Prevention.
Experience with cloud-native logging (in particular Azure and Kubernetes).
Experience of an ‘everything-as-code’, or at least a ‘detection-as-code’ approach, including CI/CD pipelines.
Exposure to working with/inside an MSP SOC.
Exposure to Agile working.
Knowledge of attacker Tactics, Techniques and Procedures (TTPs).
Knowledge of statistics, data science and AI/ML, in particular when applied to cyber security.
EDI Engineer I developing and troubleshooting software programs for healthcare solutions at Paychex. Engaging with software development life cycle and delivering software improvements in a hybrid role.
Adobe Engineer at Onebridge, responsible for implementing Adobe Target and managing digital campaigns. Collaborating with cross - functional teams to enhance digital experiences through testing and data - driven strategies.
Controls Engineer developing automation solutions for clients in high intensity environments. Joining a team of experts to solve difficult problems in industrial manufacturing.
Senior Reverse Engineer Researcher at SEI, reverse engineering malicious code and developing analysis methods. Collaborating with the security community to address emerging threats.
Sales Engineer with expertise in automation technology managing customer needs and proposals. Engaging with technical decision - makers for tailored solutions in a collaborative team environment.
Electrical Engineer overseeing investment projects for existing plants with a focus on electrical engineering. Leading project teams and ensuring project budgets and timelines.
Electrical Engineer developing HVAC solutions for data centers at Munters, focusing on energy efficiency and automation with cutting - edge technology.
Stagiaire ingénieur à FDI pour développer une plateforme de contrôle d'accès dématérialisé. Travaillant sur des projets d'innovation en R&D avec des technologies modernes.
Project Engineer I designing, developing, and installing security systems for Securitas Technology. Leading multiple projects and coordinating with customers and subcontractors in the security industry.