Threat Detection Engineer (Cloud Security)
Dark Wolf SolutionsOgdenFull TimeEngineering
Remotely
awselasticsearchsplunkkibanalogstashcloudtrailelk stackvpc flow logs
Job Description
📋 Description
- Designing, building, testing, and deploying robust detection logic using a "Detection-as-Code"
- Writing and maintaining custom detection signatures targeting cloud-native vectors, container
- Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS
- Proactively hunt for undetected malicious activity, insider threats, and novel adversary TTPs
- Partnering with NOSC operators and AWS Engineers to develop automated remediation and incident
- Conducting root-cause analysis on false positives/negatives to continuously improve alert fidelity
🎯 Requirements
- 4+ years of relevant experience
- 2+ years of hands-on experience authoring and tuning detection logic in Splunk Enterprise and the
- 2+ years of experience with employment of DoD cybersecurity requirements, policies, and procedures
- Experience within a vSOC, SOC, or CSSP responding to cyber incidents
- Direct experience ingesting, normalizing, and engineering detections for AWS GovCloud security
- Demonstrated experience using GitLab for Detection-as-Code, CI/CD pipelines, version control, and
Back to all jobs