Hybrid Threat Content Developer

Posted last month

Apply now

About the role

  • Continual assessment of the Integrity360 detection portfolio, considering strengths and weaknesses and translating them into roadmap items and priorities.
  • Ongoing analysis of various threat intelligence forms, tracking adversary activity in the context of adversary groups, campaigns, and software.
  • Tracking emerging threats, such as 0-day exploits published for popular software used across the Integrity360 customer base.
  • Continuous deployment of detection analytics (predominantly to SIEM), designed to detect any threats or risks identified during threat intelligence reviews.
  • Engage with colleagues, from teams such as Incident Response, to identify indicators which may precede successful attacks, operationalizing those indicators into new detections.
  • Contribute to the development of new tools used within the Threat Content Development team, typically leveraging automation to minimize delivery times and maximize intelligence integrations.
  • Author technical documentation, with high-level explanations and low-level details of new detections and/or systems.

Requirements

  • 3+ years hands-on technical experience within an IT security related position, such as Detection Engineer, DevSecOps Engineer, Network Security Engineer, Cyber Security Engineer, Information Security Engineer, etc.
  • Demonstrable experience implementing threat detection capabilities in security tooling such as SIEM, EDR, XDR, or SOAR.
  • Deep understanding of security frameworks such as Mitre ATT&CK, OWASP, NIST, and/or CIS.
  • Strong, low-level understanding of networking principles, operating systems, and software design practices.
  • Familiar with commonly adopted cloud technologies across different vendors (e.g. Azure, AWS, GCP).
  • Genuinely passionate about security, with a curious and analytical approach to problem solving.
  • Preferred: A working knowledge of incident response and investigation best practices, capable of identifying avenues of investigation for new detections.
  • Preferred: Capable of working with one or more programming/ scripting language, e.g. Python, PowerShell, Bash, etc.
  • Preferred: Experience working with one or more popular CI/CD tool, such as Azure DevOps or GitLab Runner, familiar with tools such as git.
  • Are you legally authorized to work full time in Bulgaria?

Benefits

  • We invest heavily in learning, development and progression
  • Dynamic culture where innovation, collaboration and continuous growth are at the heart of what we do
  • Opportunity to take your cyber security career to the next level

Job title

Threat Content Developer

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job