Remote Otter LogoRemoteOtter

Content Detection Engineer III - Remote

Posted 9 weeks ago

Overview

Agile Defense is seeking a highly-experienced SIEM Content Developer to join our team that provides security operations center (SOC) support, cyber analysis, application development, and a 24x7x365 support staff to one of our DHS.

In Short

  • Proactively search for threats and inspect traffic for anomalies.
  • Investigate and analyze logs, providing analysis and response to alerts.
  • Develop custom content within the SIEM using advanced SPL language.
  • Participate in briefings to provide expert guidance on new threats.
  • Author reports and interface with customers for ad-hoc requests.
  • Collaborate with team members to analyze alerts or threats.
  • Stay up to date with the latest threats and familiar with APT and common TTPs.
  • Provide expert guidance and mentorship to junior analysts.
  • Participate in discussions to improve SOC visibility or processes.
  • Contribute to SOP development and updating.

Requirements

  • Relevant BS degree plus 8+ years of experience in incident detection & response.
  • Experience with content development in Splunk and setting up correlation rules.
  • Experience with Crowdstrike for triaging and investigating hosts.
  • Experience with McAfee AV signatures and custom Tanium packages.
  • Ability to analyze network traffic using enterprise tools.
  • Critical thinking and analysis skills for investigating cyber security alerts.
  • Familiarity with the Cyber Kill Chain and attack life cycle.
  • Experience with dynamic malware analysis.
  • Ability to review and provide feedback to junior analysts.
  • Strong collaboration skills with team members.

Benefits

  • Opportunity to work on critical national security missions.
  • Engagement with advanced technologies and elite minds.
  • Supportive work environment with a focus on innovation.
  • Flexible working hours with on-call rotational schedule.
  • Professional development and mentorship opportunities.

Similar Jobs:

Humio ApS logo

Engineer III - Content SDET - Remote

Humio ApS

5 weeks ago

Join CrowdStrike as an Engineer III - Content SDET to develop and test cybersecurity solutions.

Python
GoLang
SQL
Test Automation
India
Full-time
Software Development

SentinelOne

Detection Engineer - Remote

SentinelOne

2 weeks ago

Join SentinelOne as a Detection Engineer to enhance malware detection and response through automation and innovative solutions.

Malware Detection
Automation
CI/CD
Scripting
India
Full-time
Software Development
Upstart logo

Detection Engineer - Remote

Upstart

3 weeks ago

Join Upstart as a Detection Engineer to enhance security through innovative alert systems and incident response.

Detection Engineering
Incident Response
Security Monitoring
LOG Analysis
USA
Full-time
DevOps / Sysadmin
$108,300 - $150,000 USD/year
Vercel logo

Content Engineer - Remote

Vercel

29 weeks ago

Join Vercel as a Technical Content Engineer to create impactful technical content for a diverse audience.

Technical Writing
WEB Development
TypeScript
Next.js
United States
Full-time
Writing
$130,000 - $169,000/year
NBCUniversal logo

Senior Detection Engineer - Remote

NBCUniversal

2 weeks ago

The Senior Detection Engineer is responsible for enhancing the organization's security posture through advanced monitoring and detection capabilities.

Cybersecurity
Detection Engineering
Threat Hunting
Incident Response
USA
Full-time
All others
$125,000 - $165,000/year