Senior Detection Engineer
Red Canary
π΅ $115k-$126k
πRemote - Worldwide
Please let Red Canary know you found this job on JobsCollider. Thanks! π
Job highlights
Summary
Join Red Canary's Cyber Incident Response Team (CIRT) as a threat analyst. You will analyze security telemetry, publish threat reports, develop detectors, automate workflows, mentor peers, and enhance the CIRT's knowledge base. The role requires experience in endpoint detection and response (EDR), cloud/SaaS security, identity security, SIEM, and strong analytical and communication skills. Familiarity with Mitre ATT&CK and various security tools is preferred. Red Canary offers a competitive salary, bonus eligibility, equity, and comprehensive benefits including 100% paid medical, dental, and vision insurance, flexible time off, paid parental leave, and a flexible work environment.
Requirements
- Analysis experience and proficiency in one or more of the following functional areas: Endpoint (MDR), Cloud/SaaS, Identity, Email, SIEM
- Proven experience with automation and orchestration to effectively handle an extreme volume of telemetry and logs in a timely and efficient manner
- Strong written communication skills, and abilities to work in a team-centric environment
- Strong analytical thought-process and critical thinking skills to translate disparate activity into the realm of threat analysis
- Open-source intelligence research skills used in a fast-paced operational environment, and the ability to apply those findings within the analytical workflow to identify threats
- Experience leveraging Mitre ATT&CK framework, and familiarity with other alternative attack frameworks and threat models
- Familiarity with backend data structures used for security analysis (JSON, YAML, etc.)
- Experience using query languages and understanding syntax across EDR or other security platforms (SQL, K, Lucene, etc.)
- Experience creating and tuning detectors/rules using commonly known tools such as YARA, SIGMA, Snort, Splunk, Elastic, etc
Responsibilities
- Use Red Canaryβs detection platform to analyze EDR telemetry, alerts, and log sources across several detection domains (Endpoint, Identity, SIEM, Cloud/SaaS, etc.) to uncover threats and tell the story of what occurred in a customer environment
- Publish threats for customers using concisely-written communication while effectively conveying key and important indicators
- Detector Development: Research coverage opportunities then create new detectors, and tune existing ones
- Improve the CIRT workflow through orchestration & automation
- Provide mentorship to your peers and communicate effectively with others for efficient cross-team collaboration
- Leverage previous SOC experience to enhance the CIRTβs knowledge-base and expertise
- Actively engage with the CIRT team to challenge the status quo for detecting adversarial behavior
- Help lead projects to improve the quality of life for both the customer and the CIRT
Preferred Qualifications
- You enjoy impacting the Infosec community through writing blogs, participating in webinars, and presenting at conference talks
- Experience using version control software for the deployment of detectors, rules, or other automations (GitHub, CircleCi, etc)
- Previous Red Team experience
Benefits
- 100% Paid Premiums: Red Canary offers a 100% paid plan option for medical, dental and vision for you and your dependents. No waiting period
- Health & Wellness - Access to mental health services, Employee Assistance Program and additional programs to incentivize healthy habits
- Fertility Benefits: All new hires are eligible for benefits as of their first day
- Flexible Time Off: Take the time you need to recharge including vacation, sick, bereavement, jury duty, and holidays
- Paid Parental Leave- Full base pay to bond/care for your new child
- Pre-Tax Plans - Red Canary offers a variety of plans to fit you and your dependent specific needs including FSA, HRA and HSA, with employer funding to offset out of pocket health care expenses
- Flexible Work Environment- With 60% remote workforce, Canaries can work virtually from almost anywhere in the US
Share this job:
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.
Similar Remote Jobs
- πSpain
- πItaly
- πPoland
- πSlovak Republic
- π°$115k-$141kπWorldwide
- π°$123k-$221kπUnited States, Canada
- πArgentina
- π°$148k-$174kπWorldwide
- π°$176k-$207kπUnited States
Please let Red Canary know you found this job on JobsCollider. Thanks! π