BCG

Global Cybersecurity Analyst - Security Engineer

BCG
Apply
2 months ago
Lisbon, PortugalSenior

Responsibilities

  • Develop and maintain production detection rules using Splunk, EDR, and other enterprise security platforms.
  • Translate red-team exercises, penetration-testing findings, and threat intelligence into production-ready detections.
  • Validate detections against enterprise telemetry and tune them to improve fidelity and reduce false positives.
  • Identify MITRE ATT&CK detection gaps and develop coverage to address them.
  • Create investigation guidance and runbooks for CSIRT and the managed security provider.
  • Partner with Security Engineering to ensure telemetry supports effective detection development.
  • Maintain detection documentation and lifecycle activities according to established standards.

Requirements

  • Experience developing and maintaining production detection rules across enterprise security platforms.
  • Strong knowledge of MITRE ATT&CK and the ability to translate adversary techniques into effective detections.
  • Advanced proficiency with Splunk SPL or similar query languages for security detection engineering.
  • Understanding of offensive security techniques and experience validating detections through purple teaming, atomic testing, or similar approaches.
  • Strong analytical skills and sound technical decision-making with incomplete or evolving information.
  • Experience collaborating with Security Operations, Incident Response, Engineering, and other technical teams.
  • A disciplined, engineering-focused approach to producing reliable, maintainable, and well-documented detection content.

Tech Stack

Splunk

Categories

BCG

About BCG

10,000+ employees
Contact me