logo inner

Detection Engineer III

SecuronixOnsite
This job is no longer open

Securonix is leading the evolution of SIEM for today’s hybrid cloud, data-driven enterprises. Securonix Unified Defense SIEM provides organizations with content-driven threat detection, investigation, and response (TDIR) solution built with a highly scalable data cloud and a unified experience from the analyst to the CISO. The innovative cloud-native solution enables organizations to scale up their security operations and keep up with evolving threats. 
Securonix Unified Defense SIEM provides organizations with 365 days of ‘hot’ data for fast search and investigation, threat content-as-a-service, proactive defense with continuous peer and partner collaboration, and a unified Threat Detection, Investigation and Response (TDIR) experience, all in a single platform. The platform is built on a cloud native architecture and leverages the power of the Snowflake Data Cloud.Job Title: Detection Engineer - 1Job Level: Individual Contributor Total Experience: 1 to 3 yearsRelevant Experience: 1+ yearsPrimary Skill Sets: Python, Log Analysis, SIEM, JIRA, Ticket ManagementSecondary Skill Sets: MITRE Framework, NOC, SOC, PlaybooksSummary:We are looking at passionate threat detection engineers who like to fight bad-guys by helping organizations detect attackers within the shortest MTD possible.

You will be part of the Securonix Detection Engineering team that is responsible for building the security analytics content, anomaly and threat detection models for the Securonix Next Generation SIEM platform and responding and providing awareness of advanced cyber and insider threats to our community. Our team's mission is to continuously develop detection methods to address the constantly-shifting threat landscape and detect the latest real-world cyberattacks.Responsibilities of the Role:

  • Learn the platform capabilities and internals to be able to support troubleshoot issues with detection content 
  • Triage customer tickets and provide technical support for issues in customer environment associated to detection content
  • Provide on-call support during weekdays and weekends
  • Proactively monitor reports and dashboards tracking content metrics from the field and flag issues
  • Help generate or collect sample logs relevant for resolution of detection tickets
  • Document RCAs for issues resolved
  • Ensure detection content is sufficiently tested and validated before pushing to production
  • Submit clear documentation around the detection content developed
  • Responsible for maintaining policies and threat-models in the Securonix platform

Skills Required:

  • At-least 1 year of prior experience in building threat detection content for SIEM platforms like ArcSight, QRadar, Splunk, LogRhythm, etc.
  • Understanding of the different MITRE ATT&CK Matrices
  • Strong fundamentals in network and operating systems concepts
  • Experience working with offensive security testing tools
  • Ability to automate basic tasks using scripting languages like Python
  • Experience in GIT and SVN based code management
  • Strong written and verbal communication skills

Additional Skills (Good to Have):

  • Prior investigations and response / SOC experience
  • Information security professional certifications (OSCP, CEH, etc.)
  • Developer or contributor to open-source attack or defense cyber-security tools 

Benefits:As a full-time employee with Securonix, you will be eligible for the following employee benefits:

  • Health Insurance with a total sum insured is INR 5,00,000
  • Coverage: Self, Spouse, 2 kids, Dependent parents, or parents-in-law
  • Personal Accident with total sum insured is INR 10,00,000
  • Term Life Insurance with a sum assured for employees is 5 times fixed base pay is covered.

Securonix, Inc. provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, amnesty or status as a covered veteran in accordance with applicable federal, state and local laws. Securonix complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.

This policy applies to all terms and conditions of employment, including hiring, placement, promotion, termination, layoff, recall, and transfer, leaves of absence, compensation and training.Securonix expressly prohibits any form of unlawful employee harassment based on race, color, religion, gender, sexual orientation, national origin, age, genetic information, disability or veteran status. Improper interference with the ability of Securonix employees to perform their expected job duties is absolutely not tolerated.

This job is no longer open

Life at Securonix

Securonix is redefining the next generation of cyber-threat detection using the power of machine learning and big data. Our purpose-built security analytics solution uses machine learning to track and create baselines of user, account, and system behavior and detects the most advanced insider threats, cyber threats, and fraud activities in real time. Securonix extends threat detection with threat-hunting and automated incident response. SOC analysts can hunt across data sources, and respond with pre-built, automated playbooks. Globally, customers use Securonix to address their insider threat, cyber threat, cloud security, fraud, and application security monitoring requirements. Securonix security analytics delivers real-time threat analysis and detection, log search, threat hunting and attack investigation via Spotter, and comprehensive case/workflow management for end-to-end security management. The solution also provides out-of-the-box integrations with existing security products. Securonix Data Lake, Next-Gen SIEM and UEBA products are offered as on-premise enterprise software or delivered via the cloud. Securonix is architected on a Hadoop big data infrastructure stack that optimizes data ingestion, context enrichment, real-time processing, and storage across separate components enabling efficient mass-scaling for large enterprises. This architecture is coupled with a new UI that realizes massive improvements in large deployments, and allows you to ingest and analyze large amounts of machine data in real-time. Securonix's Hadoop stack allows for a Google-like search at massive scale. With Hadoop clustering, SOC analysts can perform data analysis at internet-scale instantaneously, and also leverage log-searching for over 600 different commercial security, network, and application products. Securonix is privately funded by Volition Capital. Follow us on Facebook, Twitter, and LinkedIn.
Thrive Here & What We Value1. Equal Employment Opportunities (EEO)2. Nondiscrimination in employment compliance3. Prohibition of unlawful employee harassment4. No unsolicited headhunter and agency submissions for candidates5. Prior agreement required for payment to third-party agencies6. Team-oriented culture with a focus on collaboration7. Mission-first attitude8. Astute communication skills9. Critical thinking abilities10. Problem-solving capabilities
Your tracker settings

We use cookies and similar methods to recognize visitors and remember their preferences. We also use them to measure ad campaign effectiveness, target ads and analyze site traffic. To learn more about these methods, including how to disable them, view our Cookie Policy or Privacy Policy.

By tapping `Accept`, you consent to the use of these methods by us and third parties. You can always change your tracker preferences by visiting our Cookie Policy.

logo innerThatStartupJob
Discover the best startup and their job positions, all in one place.
Copyright © 2024