North AmericaFull TimeEngineering
Remotely
Listed on 2 job boards, which is a stronger signal than one board alone.
pythonawsgolangazuregcpthreat huntingci/cdsoar
Also available on
Job Description
📋 Description
- Develop, tune, document, and maintain detection logic across endpoint, cloud, container, and SaaS.
- Assist in cyber forensic investigations across log sources.
- Optimize telemetry and log ingestion to balance quality, volume, and cost.
- Design and build SOAR playbooks and automation workflows for detection triage and response.
- Mentor junior analysts and detection engineers on threat hunting and detection techniques.
🎯 Requirements
- 6+ years in detection engineering, IR, or offensive security.
- Experience with 1+ public cloud platforms (AWS, Azure, GCP).
- Deep understanding of attacker TTPs in modern environments.
- MacOS internals and telemetry knowledge for macOS threats.
- Detection-as-code with VCS, peer review, automated testing, and CI/CD.
- Basic proficiency with Python, Golang, or similar languages.
🎁 Benefits
- Remote-friendly with flexible work locations per policy.
- Pay ranges shown by location, equity grants, annual refresh grants.
- Additional benefits detailed in provided links.
Back to all jobs