Modal20 дней назад

Инженер по обнаружению и реагированию на угрозы

Зарплата не указана
РЫНОК
13 634медиана по профессии
Tech Lead / Team Lead · 356 вакансий с указанной зарплатой
5 092половина предложений: 9 708–18 1041,2 млн
Работодатель не указал зарплату — сравните с рынком сами.
Полная занятостьNew York

Обязанности

  • 01Design and build high-fidelity detections for attacks, abuse, and anomalous behavior across our infrastructure and production systems
  • 02Continuously improve detections based on telemetry, threat intelligence, and lessons learned from incidents
  • 03Improve visibility across cloud infrastructure, containers, identity systems, and production services
  • 04Lead or participate in investigations spanning production infrastructure, cloud environments, and internal systems
  • 05Build playbooks and automation that reduce investigation time and improve response consistency
  • 06Drive post-incident improvements that eliminate entire classes of future incidents
  • 07Build internal tooling that improves detection, investigation, and response workflows
  • 08Leverage LLMs to automate repetitive analysis, accelerate investigations, and surface actionable insights from security telemetry
  • 09Improve the collection, quality, and usability of security telemetry across the platform
  • 10Partner with engineering teams to ensure new systems are observable and secure by default
  • 11Help teams instrument services with the telemetry needed for effective detection and response
  • 12Drive security improvements that make the platform easier to defend over time

Требования

  • 01Experience in detection engineering, incident response, security engineering, or software engineering with a strong security focus
  • 02Strong software engineering skills with experience building production systems
  • 03Experience investigating security incidents in cloud-native or distributed environments
  • 04Familiarity with modern cloud infrastructure, Kubernetes, Linux, and networking
  • 05Experience building detections using logs, telemetry, behavioral signals, or large-scale event data
  • 06Strong SQL skills for investigating security events and developing detections
  • 07Interest in applying AI and LLMs to detection, investigation, and response, including understanding emerging threats involving AI-powered systems
  • 08Strong written and verbal communication skills