4 hours ago
Base Salary
$108k - $169k/yr
Responsibilities
- Design, build, test, tune, and deploy detection-as-code rules using KQL, Git workflows, CI, and automated deployment.
- Map detections to MITRE ATT&CK, identify coverage gaps, review Sigma and vendor rules, and improve detection quality and alert signal-to-noise.
- Plan and conduct hypothesis-driven threat hunts across cloud, SaaS, identity, endpoint, and corporate infrastructure telemetry.
- Participate in incident response by triaging, scoping, containing, and investigating incidents, then incorporating lessons into detections and playbooks.
- Maintain security log pipelines by onboarding sources, parsing and normalizing data, and monitoring for dropped, delayed, or malformed events.
- Build and maintain Cribl Stream pipelines and the automation supporting detection operations, including GitHub Actions and SIEM API integrations.
- Create processes, standards, tools, runbooks, and documentation; mentor teammates and collaborate with Product Security, IT, Infrastructure, Engineering, GRC, and Legal.
- Participate in standby, on-call, or off-hours duties.
Requirements
- At least 5 years of security operations experience with significant hands-on experience in detection engineering, threat hunting, or incident response.
- Experience writing and maintaining detections as code in a modern SIEM.
- Strong Python skills and familiarity with Git-based workflows, code review, and CI/CD.
- Strong KQL skills for writing detection queries.
- Working knowledge of MITRE ATT&CK for coverage analysis.
- Experience investigating incidents involving AWS, GCP, and/or Azure, SaaS, and identity providers.
- Hands-on experience with log pipelines, including data ingestion, parsing, and troubleshooting.
- Strong judgment in distinguishing genuine signals from noise and determining when to escalate.
- Clear technical and non-technical writing skills for incident summaries, runbooks, and detection documentation.
- Routine use of AI in engineering work, with concrete examples of its impact on building, testing, or investigation workflows.
- Preferred experience with Cribl Stream or other telemetry pipeline tools; Sigma rules; Atomic Red Team, Caldera, or similar adversary emulation; purple teaming; or agentic and AI-assisted security operations workflows.
- Certifications such as GCIH or GCDA, or equivalent experience, are a bonus.
Benefits
- Remote-first work arrangement with required standby, on-call, or off-hours duties.
- Health, dental, vision, short-term disability, and life insurance.
- Paid holidays and paid time off.
- Fertility treatment benefit.
- 401(k) and equity.
- Corporate Bonus Program eligibility for non-sales roles.
About Cribl
Cribl builds a vendor‑agnostic telemetry data platform used by IT, security, and observability teams to collect, route, shape, store, and search machine data in real time. Its products (including Cribl Stream, Edge, and Search) are sold as enterprise subscriptions and can run in cloud or self‑managed environments. Founded in 2018 and headquartered in San Francisco, the company is privately held and serves large global enterprises.
