Remotely
pythonawsgolangazuregcpci/cdmacossoar
Job Description
📋 Description
- Develop, tune, document, and maintain detection logic across log sources
- Assist in cyber forensic investigations across log sources
- Optimize log ingestion pipelines for quality data while managing cost
- Design and build SOAR playbooks and automation workflows
- Mentor junior security analysts and detection engineers
- Work with teams to reflect real-world adversary behavior
🎯 Requirements
- 6+ years in detection engineering, IR, or offensive security
- Experience with 1+ cloud platforms (AWS, Azure, GCP)
- Understanding of attacker TTPs and zero trust
- MacOS internals and telemetry knowledge
- Detection-as-code with VCS, reviews, automated tests, CI/CD
- Proficient in Python, Golang, or similar
🎁 Benefits
- Remote-friendly work policy with flexible in-person events
- Competitive compensation and benefits
- Equity grants and annual refresh grants
- Base pay varies by location; review policy here