مهندس تشخیص تهدید
Detection Engineer
قواعد تشخیصی را که SOC ما و مشتریان به آنها متکی هستند بنویسید، بیازمایید و نگهداری کنید. شما گزارشهای تهدید و درسهای حوادث را به موارد کاربرد مستند و کمهشدار تبدیل میکنید.
متن کامل آگهی به انگلیسی است. میتوانید درخواست خود را به زبان خودتان ارسال کنید.
About the role
Good monitoring depends on detections that fire on real threats and stay quiet otherwise. This role owns that content for our SOC and for clients who run their own. You analyse threat intelligence and incident findings, write detection logic for SIEM and EDR platforms, and test it against realistic data before release. You work with SOC analysts, incident responders and client security teams, and you keep a versioned library that others can review and reuse.
What you will do
- Develop and maintain detection rules in KQL, SPL or Sigma, mapped to MITRE ATT&CK
- Manage detection content as code with peer review, testing and version control
- Measure coverage and false positive rates and tune rules with SOC feedback
- Onboard new log sources and define the parsing and normalisation they need
- Document use cases and response guidance so analysts know what each alert means
What you bring
- 3+ years in a SOC, detection engineering or security monitoring role
- Hands-on experience with Microsoft Sentinel, Splunk or Elastic Security
- Good knowledge of Windows event logs, identity platforms and cloud audit logs
- Scripting skills in Python or PowerShell
- Working knowledge of MITRE ATT&CK and how to use it for coverage planning
Good to have
- Experience with detection-as-code pipelines in Git
- GIAC certification such as GCDA or GCIA
Languages
English (C1), German or French (B1) an advantage
Skills
این صفحه با کمک هوش مصنوعی ترجمه شده است. در صورت هرگونه ابهام، نسخهٔ انگلیسی ملاک است.