About the job
The Detection Engineer will be a pivotal member of the Cyber Incident Response Team (CIRT) within our Information Security division.
Key Responsibilities include:
- Designing, engineering, and implementing security detection initiatives under the guidance of the cybersecurity team lead.
- Developing advanced detection logic for SIEM (Microsoft Sentinel) and network security platforms (Cisco FirePower, IDS/IPS), utilizing AI-driven tools where applicable.
- Crafting and optimizing KQL queries for Sentinel to enhance detection accuracy and minimize false positives.
- Tuning detection sets to elevate security-relevant events for triage and response teams.
- Managing version control of detection logic using Git and GitHub workflows to ensure collaborative development and auditability.
- Facilitating communication between network engineering and cybersecurity teams to promote secure network designs and maximize security device effectiveness.
- Conducting technical briefings to bolster team awareness of network architecture and detection methodologies.
- Collaborating with operations and management to recommend enhancements to security posture and ensure adherence to industry and federal standards (e.g., NIST, CISA).
