Senior Cloud Cybersecurity Detection And Response Engineer
Tanium
Job highlights
Summary
Join Tanium as a Senior Cloud Cybersecurity (CCS) Detection and Response Engineer and collaborate with engineers to proactively defend Tanium Cloud services. You will design, implement, and operate preventative, detective, and responsive controls to mitigate risks and threats. Responsibilities include building and operating detection and response engineering, enhancing cloud security measures, characterizing unauthorized activity, developing detection policies, integrating security threats and trends, collaborating with other teams, and being on-call for critical events. The role requires a Bachelor's degree or equivalent experience in a relevant field, 5-7 years of cloud security experience, 3+ years of Kubernetes experience, and expertise in security tools and methodologies. Preferred qualifications include experience in specific cloud platforms and security certifications. Tanium offers a competitive salary and benefits package, including volunteer time off.
Requirements
- Bachelor's degree or equivalent experience
- 5-7 years of experience in cloud security event prevention, detection, response for public cloud systems (e.g. AWS, Azure) within a DevOps environment
- 3+ years of hands-on experience in Kubernetes environment, logging, and runtime security for sensitive container workloads, preferably on AKS and EKS
- Experience in detection and response engineering methodologies, such as building detection cases, proactively identify known and unknown cyber threats, advisory behaviors
- Experience in using security query or analytic tools for security data analysis, such as SQL, KQL, or SPL
- Build and improve security playbooks and runbooks for automating security detection and response
- Solid understanding of modern attacker tactics, techniques, and procedures (TTPs) against Kubernetes, Container, Serverless, Linux host, and Cloud services (e.g. MITRE ATT&CK, building threat intelligence, etc.)
- Experience with security events and incident management in highly regulated hosting environments (such as ISO 27001, NIST SP 800-161r3, FedRAMP, Protected B)
- Utilize robust analytical and problem-solving capabilities to confirm our hypotheses using precise data and in-depth root cause investigation
- Experience using high-level programming languages (Go, Python) to produce detection-as-code, tools, and automations
- Experience managing cloud infrastructure as infrastructure-as-code (e.g. Terraform, CloudFormation, ARM, Pulumi)
- Deliver high quality PRs daily using modern software engineering development and automation tools like Git and CI/CD pipelines (i.e. Jenkins, GitHub Actions)
- Deliver quality and velocity of contributions using DevOps principles
- Relentless desire to automate the mundane to focus on solving the harder problems
- Experienced engineer who can put out fires under pressure when things go wrong in production environments and address the root causes of those fires for the future
Responsibilities
- Build and operate Tanium Cloud's detection and response engineering in Azure, AWS, and Kubernetes for detections, analysis, and responses as automation as code using DevOps methodologies
- Continuously evaluate and enhance the design and effectiveness of Cloud and Kubernetes security measures and establish an ongoing program to advance security and close gaps in our defensive posture
- Proactively characterize unauthorized activity and malicious behaviors in our cloud and container infrastructure and systems through code, testing, and automation
- Develop tailored detection policies, perform testing, and implement automation to observe, evaluate, enhance, and review security information using SecDataOps and best practices
- Proactively integrate the latest security threats, vulnerabilities, and industry trends to enhance security detection measures and generate intelligence driven hunts
- Work together with the engineering, IT, and other security groups to create solutions that are expandable and adaptable to protect Tanium Cloud against threats ranging from low-level actors to national cyber-threat agents
- Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work
- Be on periodic on-call for triage of critical events from detections and systems
Preferred Qualifications
Cloud Security, IT Security, or related technical field
Benefits
- 5 days of volunteer time off (VTO)
- Annual base salary range for this full-time position is $C95,000 to $C280,000
Share this job:
Similar Remote Jobs
- π°$93k-$135kπIreland
- π°$180k-$210kπWorldwide
- πGermany
- πIndia
- πWorldwide
- π°$140k-$150kπWorldwide
- π°$185k-$220kπUnited States
- π°$162k-$221kπUnited States
- π°$148k-$174kπWorldwide