Stellenangebot
Detection Engineer
Der Detection Engineer entwickelt und implementiert fortschrittliche Mechanismen zur Erkennung von Cyber-Bedrohungen und arbeitet eng mit Sicherheitsteams zusammen, um potenzielle Bedrohungen zu antizipieren und zu entschärfen. Der Schwerpunkt liegt auf der Erstellung von Detection-Content, der Automatisierung von Prozessen und der kontinuierlichen Verbesserung der Sicherheitssysteme.
Stellenbeschreibung
Job-Titel:
Detection EngineerJob-Details:
- Arbeitsmodell: Hybrid
- Arbeitszeit: Vollzeit
- Standorte: Naperville, IL, Chicago, IL
Aufgaben:
- Build, refine, and manage detection content to identify and mitigate potential threats.
- Develop a Detection-as-Code standard using code repositories and CI/CD pipelines to streamline content deployment via Infrastructure-as-Code methodologies.
- Work closely with various teams in Security Operations to anticipate and detect potential threats before they fully materialize.
- Participate in continuous improvement initiatives to enhance detection capabilities and efficiency.
- Develop and maintain documentation for detection logic, use cases, and response playbooks.
- Maintain up-to-date knowledge of the latest cybersecurity threats, tools, and best practices.
- Contribute to automation of detection and response processes using SOAR platforms.
Anforderungen:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 3+ years of experience in cybersecurity, preferably in detection engineering, threat hunting, or incident response
- Proficiency in writing and tuning detection logic in SIEM platforms (e.g., Splunk, Sentinel, Elastic).
- Strong understanding of cyber security principles, including SIEM, IDS/IPS, and endpoint detection and response (EDR) solutions.
- Experience with coding/scripting languages such as Python, PowerShell, or Bash.
- Familiarity with CI/CD pipelines, code repositories (e.g., Git), and Infrastructure-as-Code tools (e.g., Terraform, Ansible).
- Excellent problem-solving skills and attention to detail.
- Strong communication and documentation abilities.
Bevorzugte Qualifikationen:
- Experience in a cloud environment (e.g., AWS, Azure, GCP).
- Knowledge of malware analysis, reverse engineering, and digital forensics.
- Experience with performing insider threat analysis and detections
- Knowledge of security orchestration and automation platforms
Wir bieten:
- Gehaltsspanne: $114,500 - $194,700 USD
- Flexible und kollaborative Arbeitskultur
- Karriereentwicklung und Weiterbildung
- Einbindung in eine weltweit anerkannte und preisgekrönte Finanzinstitution
Sonstiges:
- Northern Trust ist bestrebt, Menschen mit Behinderungen zu unterstützen und angemessene Vorkehrungen zu treffen.
Jobdetails