
Senior Security Engineer,Detection & Incident Response
Pure Storage7 hours ago
Prague, CzechiaSenior
Responsibilities
- Design, implement, maintain, test, and tune detections in Splunk and related security platforms using detection-as-code formats and MITRE ATT&CK coverage.
- Investigate suspicious activity and execute incident triage, scoping, containment, eradication, recovery, and post-incident reviews.
- Conduct hypothesis-driven threat hunts using threat intelligence, behavioral baselines, anomaly detection, the Diamond Model, and kill chains.
- Build Python scripts, API integrations, enrichment workflows, and SOAR automations to accelerate investigation and containment.
- Monitor and investigate security signals across AWS, GCP, Azure, cloud services, containers, Kubernetes, identity, endpoints, networks, and SaaS.
- Operationalize cyber threat intelligence and translate adversary tools, techniques, procedures, and indicators into detection and hunting strategies.
- Evaluate and implement AI-assisted security workflows, including LLM-based investigations and autonomous triage, with human oversight and guardrails.
- Develop detection playbooks, investigation procedures, automated security playbooks, operational runbooks, and Git-backed detection repositories.
- Collaborate with global Security Operations teams in a 24/7, follow-the-sun security operations environment.
- Work primarily from the Prague, Czech Republic office.
Requirements
- 6+ years of experience in cybersecurity, incident response, detection engineering, security operations, or a related security discipline.
- 3+ years of hands-on experience with threat hunting, complex incident investigations, or detection engineering in a SOC or SIEM environment.
- Deep hands-on Splunk experience, including searches, dashboards, alerts, correlation searches, saved searches, deployment server, and forwarder management.
- Strong understanding of the incident response lifecycle, networking, operating systems, cloud environments, security architecture, identity, endpoints, and networks.
- Experience developing Python scripts for data processing, API integrations, security tooling, and automation.
- Strong knowledge of threat intelligence, MITRE ATT&CK, the Diamond Model, kill chains, TTPs, hypothesis-driven hunting, behavioral baselines, and anomaly detection.
- Excellent written and verbal communication skills in English.
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.
- Preferred experience with Sigma, ECMA/JSON detection formats, Git-backed detection repositories, unit testing, Splunk Security Content, Tines, XSOAR, Splunk SOAR, AWS, GCP, Azure, CloudTrail, GuardDuty, containers, Kubernetes, Falco, Terraform, CloudFormation, attack surface management, or AI-assisted security workflows.
- Preferred certifications include GCIH, GCIA, AWS Security Specialty, or CKS.
Benefits
- Flexible time off, wellness resources, and company-sponsored team events.
- Growth and development support, inclusive employee resource groups, and a collaborative team culture.
- Primarily in-office work from the Prague, Czech Republic location, with exceptions for PTO, work travel, or approved leave.
Tech Stack
Categories
About Pure Storage
Pure Storage builds all-flash data storage systems and software for enterprises, including FlashArray and FlashBlade, and offers storage delivered as-a-service for on‑prem and cloud workloads. Its subscription model (Evergreen/Pure as‑a‑Service) supports databases, virtualization, analytics, and AI. Founded in 2009 and headquartered in Santa Clara, California, Pure is a public company listed on the NYSE (PSTG).