Senior Cybersecurity Engineer (Detection / IR) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Pellera Technologies ยท 3 days ago

Senior Cybersecurity Engineer (Detection / IR)

Pellera Technologies is seeking a Senior Cybersecurity Engineer within their Cybersecurity Strategy & Defense practice. The role involves providing expertise in defensive cybersecurity operations, including proactive threat hunting and incident response, while also customizing security solutions for clients.

Cloud SecurityCyber SecurityInformation TechnologyNetwork Security

Responsibilities

Provide day to day support for enterprise level security solutions in the cloud such as SIEM, EDR, Vulnerability Management, etc
Become the technical lead and conduit between client security operations and external SOC team
Conduct proactive threat hunting across cloud and hybrid environments utilizing the MITRE ATT&CK framework
Create and conduct threat modeling and adversary simulations to identify detection gaps and improve SOC coverage
Manage and investigate alerts & incidents using EDR/XDR toolset
Build complex queries and custom hunting use cases
Conduct incident response, root cause analysis and post-incident reporting including collaboration with stakeholders and regulatory compliance team
Troubleshoot product issues as they arise
Evaluate and recommend new and emerging services and technologies

Qualification

SIEM managementEDR expertiseThreat huntingIncident responseMITRE ATT&CK frameworkCloud security solutionsNetworking protocolsRoot cause analysisRegulatory compliancePost-incident reportingData connector managementCustom hunting use casesProduct troubleshootingAdversary simulationsAnalytics rules tuningEmerging technologies evaluationCollaboration with stakeholdersTrainingDevelopment

Required

5+ years of experience in a professional cybersecurity capacity
5+ years of experience working with SIEM and EDR solutions
Strong proficiency in building, tuning and managing analytics rules, workbooks, hunting queries and playbooks
Demonstrated experience conducting proactive threat hunting across cloud and hybrid environments using MITRE ATT&CK framework
Solid understanding of log ingestion pipelines, normalization schemas (like ASIM), and data connector management within SIEM tools
Deep familiarity with common attacker techniques, tactics, and procedures (TTPs), and the ability to translate them into high-fidelity detection logic
Strong grasp of core networking protocols and security technologies, including DNS, TCP/IP, HTTP(S), TLS, IPSec, and firewalls

Preferred

Azure Sentinel preferred
Crowdstrike preferred
Azure Security and Crowdstrike certifications are preferred
Industry leading certifications are a plus, especially via GIAC / SANS

Benefits

Healthcare benefits
401k match
PTO/holiday
Training/development
Promotional opportunity

Company

Pellera Technologies

twittertwitter
company-logo
Pellera Technologies is an information technology company that offers cloud, cybersecurity, digital infrastructure, and managed services.