Threat Detection Engineer

Legato Security

$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent experience.
  • 3-5 years in detection engineering or related fields such as SOC Analyst or Software Development.
  • Knowledge of networking principles and protocols.
  • Basic understanding of Windows OS and common exploits.
  • Familiarity with Active Directory and common attacks.
  • Interest in detection engineering and ability to learn new tools quickly.
  • Strong communication skills and ability to prioritize tasks.

Responsibilities

  • Create and refine detection rules in various SIEMs through log reviews.
  • Maintain documentation for detection workflows and procedures.
  • Collaborate with SOC analysts to enhance detection accuracy.
  • Update detection use cases based on new threats and customer logs.
  • Generate reports on detection performance metrics.
  • Respond to internal and customer requests related to detection engineering.
  • Contribute to projects focusing on detection as code.

Benefits

  • Startup culture with growth opportunities based on performance.
  • Flexible Paid Time Off policy.
  • Competitive medical and dental benefits for employees and family.
  • Voluntary benefits including life insurance and short-term disability.
  • Professional development opportunities tailored to the role.
Full Job Description
Threat Detection Engineer

Position Overview

Legato Security is seeking a motivated junior or mid-level Detection Engineer to assist with detection engineering efforts. As a Detection Engineer, you will assist with rule creation, rule tuning, creating documentation, assisting with on-going infrastructure projects, and assisting with customer requests.

Specific Job Responsibilities
  • Create, improve, review, and tune detection rules in various SIEMs (e.g., Sumo Logic, Google SecOps, Stellar Cyber). This will include log reviews of customer environments to make informed decisions.
  • Assist in creating and maintaining documentation for detection procedures, workflows, and active projects.
  • Collaborate with SOC analysts to improve detection accuracy and reduce false positives
  • Help maintain and update detection use cases based on emerging threats and customer-specific logs.
  • Assist in creating regular reports on detection metrics and effectiveness.
  • Review and respond to internal and customer requests to assist with anything related to detection engineering.
  • Contribute to declarative and imperative programming projects to assist with detection as code.

Qualifications

Required Qualifications:
  • Bachelor's degree in Computer Science, Cybersecurity, related field or equivalent industry experience
  • 3-5 years of experience in detection engineering or a related field (e.g., SOC Analyst, Pen Testing, IT Infrastructure, Network Engineering, or Software Development). Job-specific experience in detection engineering is not required
  • Familiarity with networking principals (e.g. routing, common protocols, firewall functionality, etc.)
  • Basic understanding of Windows operating systems (e.g. versions, common exploits, understanding of registries, exposed protocols, common enumeration commands, etc.)
  • Active Directory Fundamentals (e.g. basic understanding of NTLM and Kerberos, how to use LDAP, understanding of common attacks within Active Directory.)
  • Understanding of Detection as Code and common exploits
  • Strong interest in pursuing a career in detection engineering
  • Ability to quickly learn different tool sets and environments
  • Strong written and verbal communication skills
  • Ability to prioritize multiple competing projects, meet deadlines, and work effectively in a team environment

Preferred Qualifications:
  • Applicants who demonstrate personal learning and curiosity through personal projects will be prioritized. e.g. home labs, personal Github projects, write-ups, blog posts, Hack the Box profile, TryHackMe profile.
  • Relevant certifications such as OSCP (Offsec), OSDA (Offsec), CPTS (HTB), CDSA (HTB), etc.

Perks
• Start-up company in a growth phase with opportunity for advancement based on performance
• Start-up culture with an office in downtown Salt Lake City, UT
• Competitive medical and dental benefits for employee and family members
• Other voluntary benefits such as short-term disability, life insurance, children's orthodontia, with additional voluntary benefits available
• Flexible Paid Time Off policy
• Professional Development opportunities specific to role

Similar Jobs

More Jobs at Legato Security

  • Threat Detection Engineer
    $80K — $95K *
    Salt Lake City, UT 84118 (Salt Lake County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Threat Detection Engineer jobs: