2 months ago
Lisbon, PortugalSenior
Responsibilities
- Develop and maintain production detection rules using Splunk, EDR, and other enterprise security platforms.
- Translate red-team exercises, penetration-testing findings, and threat intelligence into production-ready detections.
- Validate detections against enterprise telemetry and tune them to improve fidelity and reduce false positives.
- Identify MITRE ATT&CK detection gaps and develop coverage to address them.
- Create investigation guidance and runbooks for CSIRT and the managed security provider.
- Partner with Security Engineering to ensure telemetry supports effective detection development.
- Maintain detection documentation and lifecycle activities according to established standards.
Requirements
- Experience developing and maintaining production detection rules across enterprise security platforms.
- Strong knowledge of MITRE ATT&CK and the ability to translate adversary techniques into effective detections.
- Advanced proficiency with Splunk SPL or similar query languages for security detection engineering.
- Understanding of offensive security techniques and experience validating detections through purple teaming, atomic testing, or similar approaches.
- Strong analytical skills and sound technical decision-making with incomplete or evolving information.
- Experience collaborating with Security Operations, Incident Response, Engineering, and other technical teams.
- A disciplined, engineering-focused approach to producing reliable, maintainable, and well-documented detection content.
Tech Stack
Splunk
