SIEM Detection Engineer

Insight Global

$90K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-15+ years of experience in Information Security, particularly in large enterprises (20,000+ endpoints)
  • 4+ years focused on Detection Engineering
  • Proficient in managing alerts and tuning policies for Microsoft Sentinel (SIEM)
  • Understanding of the MITRE ATT&CK framework
  • Experience in risk measurement, reporting, and remediation
  • Strong communication and problem-solving skills
  • Experience deploying security solutions on MS Defender for Endpoint, Linux Redhat, and Windows Servers

Responsibilities

  • Manage detection context and create alerts for various systems
  • Tune existing alerts to improve detection and response
  • Monitor and analyze trending data to identify potential threats
  • Implement feedback from the SOC team to enhance detection capabilities
  • Collaborate cross-functionally during 2-week sprint cycles to improve security posture

Benefits

  • Medical, dental, and vision insurance starting from the 31st day of employment
  • Health Savings Account (HSA), Flexible Spending Account (FSA), and Dependent Care FSA options
  • 401k retirement account access with employer matching
  • Paid sick leave and other legally applicable paid time off
Full Job Description
Insight Global is looking for a Detection Engineer consultant focused on managing detection context. This environment will be running in 2-week sprints, and working cross functionally with the SOC. You will be responsible for building alerts, tuning alerts, keeping an eye on trending data, and implementing feedback from SOC team.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Required Skills & Experience
- 5-15+ years of experience within Information Security working within large enterprises (20,000+ endpoints)
- 4+ years of working experience focused within Detection Engineering
- Experience working with managing alerts, and tuning policies for Microsoft Sentinel (SIEM)
- MITRE ATT&CK framework understanding
- Risk measurement, reporting, remediation
- Good communication and problem solving skills
- MS (Microsoft) Defender for Endpoint security deployed for servers
- Linux Redhat and Windows Servers, experience deploying and securing
- Building detection content for the SIEM environment

Nice to Have Skills & Experience
- Splunk, LogRhythm, Arcsight
- Experience working for a large Canadian Bank

Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.

Similar Jobs

More Information Technology Jobs

Find similar SIEM Detection Engineer jobs: