Senior Detection Engineer, Threat Detection & Monitoring

closed
AbbVie Logo

AbbVie

πŸ“Remote - United States

Summary

Join AbbVie as a Senior Detection Engineer and be responsible for executing the Business Application Security Monitoring (BASM) service. This technical role focuses on extending AbbVie’s Threat Detection and Monitoring (TDM) services to business web applications, serving as a technical subject matter expert on attacker tactics and techniques. You will coach junior team members, perform advanced data analysis, collaborate with Incident Response teams and application owners, and create threat detection content. The position can be located anywhere in the U.S. and involves collaborating with application owners to understand application design and implementation details. You will implement detection rules using application telemetry and logs in the SIEM. This role requires strong technical expertise in web application security and data analysis.

Requirements

  • Bachelors Degree and 7 years experience OR Masters Degree and 6 years experience OR PhD and 2 years experience of specialized information security experience
  • Expertise in performing data analysis using a modern SIEM, including ability to interpret log data to infer application activity, user actions, and anomalies
  • Ability to successfully interact with non-technical in-business contacts
  • Strong business acumen and an ability to assess, understand, and articulate technical impact and risk to a diverse audience
  • Deep knowledge of cloud hosting solutions and its use in web application development
  • Strong knowledge of web application architectures, various hosting platforms, major operating systems, typical web application network protocols, systems administration, and web application security technologies
  • In depth knowledge of key web application related concepts such as SAML, SSO, OAuth, MFA, SSL/TLS, etc
  • Strong knowledge and application of cyber security terminology and concepts, and general understanding of the cyber threat landscape and attack vectors
  • Thorough understanding of the MITRE ATT&CK framework and its practical applications
  • Willingness to be available, as needed, for critical and major security issues
  • Ability to author technical documentation and perform quality assurance reviews of documents created by peers
  • Demonstrate critical thinking, problem-solving, and analytical skills; investigates, defines, and resolves critical issues
  • Regularly collaborate with peers as well as business and IT stakeholders in support of daily activities
  • Strong organization skills with attention to details
  • Strong written and verbal communication skills with a high level of professionalism
  • Ability to work independently and effectively as part of a team. Ability to execute with limited guidance and contribute to decisions based on specialized knowledge

Responsibilities

  • Onboarding new business application for security monitoring by following the application on-boarding process
  • Ensuring application logs meet the minimum logging requirements to enable standard monitoring use-cases
  • Collaborating with application SMEs to gain deeper understanding of application design and implementation, including identification of specific areas of security concern
  • Performing data exploration and advanced data analysis to implement application-specific custom monitoring use-cases
  • Executing the detection content lifecycle, including developing, analyzing, documenting, and maintaining detection content by following the TDM processes
  • Fostering a collaborative relationship with business application SMEs during and following the application security monitoring enrollment
  • Supporting and encouraging application teams to adopt enterprise SIEM to perform operational monitoring of their critical apps
  • Lending technical expertise and helping coordinate defensive toolset engineering, including content creation, tuning, expansion of defensive platforms, and implementation of new controls
  • Maintaining a solid command of various web application architectures and hosting platforms, including SaaS, IaaS, on-prem, dynamic and no-code/low-code workloads
  • Collaborating with specialists and analysts to actively contribute to risk reduction efforts, including but not limited to assessments and in-depth research and analysis of threats
  • Providing recommendations and influencing decisions made by leadership for improving program maturity

Benefits

  • Paid time off (vacation, holidays, sick)
  • Medical/dental/vision insurance
  • 401(k)
  • Short-term incentive programs
  • Long-term incentive programs
This job is filled or no longer available

Similar Remote Jobs