Pure Storage

Senior Security Engineer,Detection & Incident Response

Pure Storage
Apply
7 hours ago
Prague, CzechiaSenior

Responsibilities

  • Design, implement, maintain, test, and tune detections in Splunk and related security platforms using detection-as-code formats and MITRE ATT&CK coverage.
  • Investigate suspicious activity and execute incident triage, scoping, containment, eradication, recovery, and post-incident reviews.
  • Conduct hypothesis-driven threat hunts using threat intelligence, behavioral baselines, anomaly detection, the Diamond Model, and kill chains.
  • Build Python scripts, API integrations, enrichment workflows, and SOAR automations to accelerate investigation and containment.
  • Monitor and investigate security signals across AWS, GCP, Azure, cloud services, containers, Kubernetes, identity, endpoints, networks, and SaaS.
  • Operationalize cyber threat intelligence and translate adversary tools, techniques, procedures, and indicators into detection and hunting strategies.
  • Evaluate and implement AI-assisted security workflows, including LLM-based investigations and autonomous triage, with human oversight and guardrails.
  • Develop detection playbooks, investigation procedures, automated security playbooks, operational runbooks, and Git-backed detection repositories.
  • Collaborate with global Security Operations teams in a 24/7, follow-the-sun security operations environment.
  • Work primarily from the Prague, Czech Republic office.

Requirements

  • 6+ years of experience in cybersecurity, incident response, detection engineering, security operations, or a related security discipline.
  • 3+ years of hands-on experience with threat hunting, complex incident investigations, or detection engineering in a SOC or SIEM environment.
  • Deep hands-on Splunk experience, including searches, dashboards, alerts, correlation searches, saved searches, deployment server, and forwarder management.
  • Strong understanding of the incident response lifecycle, networking, operating systems, cloud environments, security architecture, identity, endpoints, and networks.
  • Experience developing Python scripts for data processing, API integrations, security tooling, and automation.
  • Strong knowledge of threat intelligence, MITRE ATT&CK, the Diamond Model, kill chains, TTPs, hypothesis-driven hunting, behavioral baselines, and anomaly detection.
  • Excellent written and verbal communication skills in English.
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent practical experience.
  • Preferred experience with Sigma, ECMA/JSON detection formats, Git-backed detection repositories, unit testing, Splunk Security Content, Tines, XSOAR, Splunk SOAR, AWS, GCP, Azure, CloudTrail, GuardDuty, containers, Kubernetes, Falco, Terraform, CloudFormation, attack surface management, or AI-assisted security workflows.
  • Preferred certifications include GCIH, GCIA, AWS Security Specialty, or CKS.

Benefits

  • Flexible time off, wellness resources, and company-sponsored team events.
  • Growth and development support, inclusive employee resource groups, and a collaborative team culture.
  • Primarily in-office work from the Prague, Czech Republic location, with exceptions for PTO, work travel, or approved leave.
Pure Storage

About Pure Storage

1,001-5,000 employees

Pure Storage builds all-flash data storage systems and software for enterprises, including FlashArray and FlashBlade, and offers storage delivered as-a-service for on‑prem and cloud workloads. Its subscription model (Evergreen/Pure as‑a‑Service) supports databases, virtualization, analytics, and AI. Founded in 2009 and headquartered in Santa Clara, California, Pure is a public company listed on the NYSE (PSTG).

Contact me