Threat Detection Engineer Full time Job in San Antonio, Texas United States | Snaprecruit

Threat Detection Engineer Full time Job in San Antonio, Texas United States | Snaprecruit
  • Snapboard
  • Activity
  • Reports
  • Campaign
Welcome ,

Threat Detection Engineer

In Texas United States

Save this job

Threat Detection Engineer   

JOB TITLE:

Threat Detection Engineer

JOB TYPE:

Full-time

JOB LOCATION:

San Antonio Texas United States

JOB DESCRIPTION:

Job Title

Threat Detection Engineer

Relevant Experience

(in Yrs)

6+

Technical/Functional Skills

ELK stack, Fireeye HX, Sysmon, Winlogbeat

Experience Required

6+

Roles & Responsibilities

Technical knowledge to write & develop rules for CIRT analysis, experience on ELK stack, Fireeye HX, Sysmon, Winlogbeat, CI-CD pipeline.

Deep understanding of cyber threat actor attacker techniques and tools (such as malware, common attack types) including evasion techniques, reconnaissance, scanning, exploitation, evasion, lateral movement, persistence, and exploits), proficient with MITRE ATT&CK

Deep understanding of security operations center processes, tools, and data for analysis & control mitigations, security event timeline analysis and baselining with experience in the analysis of logs and data for the development and implementation of custom detections to counter attacker techniques, known vulnerabilities and evasion methods

Security architecture (network topology, firewalls, proxies, web content filtering, wireless, EDR, IDS, IPS, SIEM, SOAR, etc.
)

Network data sources (full packet analysis, flow data, dns logs, proxy logs, NIDS, etc.
)

Knowledge and experience with common scripting languages and tools Python, PowerShell, Bash, YAML

Deep knowledge of compound logical operations (AND, OR, NOT), regular expressions

Experience extracting data from logs, SQL, and APIs

Knowledge and experience with tools used to build threat detections (Elastalert, Logstash, Kibana (ELK), Fireeye HX, Sysmon, Winlogbeat, Linux Auditd)

Deep understanding and experience with Operating Systems Including: Administration, configuration, registry, processes (Windows, Mac, and Linux)

Experience in red team/blue team/incident responder interaction

Position Details

POSTED:

Nov 25, 2023

EMPLOYMENT:

Full-time

SNAPRECRUIT ID:

S110309-9119-11182023-39769444

LOCATION:

Texas United States

CITY:

San Antonio

Job Origin:

CEIPAL_ORGANIC_FEED

Jobcon Logo
A job sourcing event
In Dallas Fort Worth
Aug 19, 2017 9am-6pm
All job seekers welcome!

Threat Detection Engineer    Apply

Click on the below icons to share this job to Linkedin, Twitter!

Job Title

Threat Detection Engineer

Relevant Experience

(in Yrs)

6+

Technical/Functional Skills

ELK stack, Fireeye HX, Sysmon, Winlogbeat

Experience Required

6+

Roles & Responsibilities

Technical knowledge to write & develop rules for CIRT analysis, experience on ELK stack, Fireeye HX, Sysmon, Winlogbeat, CI-CD pipeline.

Deep understanding of cyber threat actor attacker techniques and tools (such as malware, common attack types) including evasion techniques, reconnaissance, scanning, exploitation, evasion, lateral movement, persistence, and exploits), proficient with MITRE ATT&CK

Deep understanding of security operations center processes, tools, and data for analysis & control mitigations, security event timeline analysis and baselining with experience in the analysis of logs and data for the development and implementation of custom detections to counter attacker techniques, known vulnerabilities and evasion methods

Security architecture (network topology, firewalls, proxies, web content filtering, wireless, EDR, IDS, IPS, SIEM, SOAR, etc.)

Network data sources (full packet analysis, flow data, dns logs, proxy logs, NIDS, etc.)

Knowledge and experience with common scripting languages and tools Python, PowerShell, Bash, YAML

Deep knowledge of compound logical operations (AND, OR, NOT), regular expressions

Experience extracting data from logs, SQL, and APIs

Knowledge and experience with tools used to build threat detections (Elastalert, Logstash, Kibana (ELK), Fireeye HX, Sysmon, Winlogbeat, Linux Auditd)

Deep understanding and experience with Operating Systems Including: Administration, configuration, registry, processes (Windows, Mac, and Linux)

Experience in red team/blue team/incident responder interaction

Loading
Please wait..!!