Threat Detection Engineer
US Remote
WHAT IS BOX?
Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish ourselves as leaders in the space, and we need strong advocates to help us achieve that goal.
By joining Box, you will have the unique opportunity to help capture a majority of this developing market and define what content management looks like for the digital enterprise. Today, Box powers over 97,000 businesses, including 70% of the Fortune 500 who trust Box to manage their content in the cloud.
WHY BOX NEEDS YOU
The Threat Detection Engineer is responsible for threat hunting and detection within the Threat Operations Team. This role will collaborate with other teams within Security Operations, IT, and Engineering to identify and remediate detection gaps. The Detection Engineer will also work with the Intelligence Team to assess and prioritize behaviors to hunt and build automated detections.
WHAT YOU'LL DO- Build, test and deploy detection analytics based on research of novel attack techniques and real world threats to Box.
- Work closely with our Incident Response Team to improve the fidelity, context and automation of new and existing alerting.
- Identify and assist service owners with logging configuration to eliminate gaps in logging visibility.
- Work closely with our Offensive Security Team to identify and develop solutions for gaps in detection coverage.
- Participate in Purple Team exercises to improve and validate detections
- Work closely with our Intelligence Team to focus detection efforts on prioritized threat behaviors.
- Participate in after hours on-call rotation when required
- A Bachelors degree in computer science, cybersecurity, mathematics, data science or related fields, or equivalent work experience.
- 4+ years of experience in a security operations role.
- You are comfortable (and enjoy!) searching through TB's of data in a SIEM to find interesting patterns (i.e. Splunk, ELK, etc.).
- You are familiar with Splunk Processing Language (SPL) or SQL and want to become a power user.
- You have worked as an incident responder or have partnered closely with an incident response team.
- You are comfortable writing small scripts in python or similar scripting languages.
- You have an understanding of how attackers leverage commonly used MITRE ATT&CK techniques and common ways to detect them.
- You are familiar with reviewing logs from various Operating Systems (MacOS, Linux, Windows)
- Visit this webpage to check out all of our exciting healthcare benefits: https://join.collectivehealth.com/box
- For all other benefits, please check out: Box Benefits + Perks
Job perks/benefits:
Health care
Job regions:
Remote/Anywhere
North America
Job country:
United States
Job stats:
12
0
1
Other jobs like this
Explore more Cyber Security career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.
- Open Cyber Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Penetration Tester jobs
- Open Senior DevSecOps Engineer jobs
- Open Application Security Engineer/Architect jobs
- Open Senior Security Operations Engineer jobs
- Open Cyber Threat Intelligence Analyst jobs
- Open Head of Information Security jobs
- Open Senior Information Security Engineer jobs
- Open Lead Security Engineer jobs
- Open Staff Security Engineer jobs
- Open SOC Analyst jobs
- Open Cyber Security Analyst jobs
- Open Information System Security Officer (ISSO) jobs
- Open Cybersecurity Engineer jobs
- Open Senior Penetration Tester jobs
- Open Sr. Security Engineer jobs
- Open Senior Threat Intelligence Analyst jobs
- Open Cloud Security Automation Specialist jobs
- Open Offensive Security Engineer jobs
- Open Information Security Officer jobs
- Open Azure Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cloud Security Operations Lead jobs
- Open Cybersecurity Analyst jobs
- Open DevOps-related jobs
- Open Application security-related jobs
- Open Analytics-related jobs
- Open Audits-related jobs
- Open PCI-related jobs
- Open OWASP-related jobs
- Open Threat intelligence-related jobs
- Open Clearance-related jobs
- Open Security assessments-related jobs
- Open IDS-related jobs
- Open Forensics-related jobs
- Open JavaScript-related jobs
- Open Splunk-related jobs
- Open Ruby-related jobs
- Open Encryption-related jobs
- Open CEH-related jobs
- Open CISM-related jobs
- Open GDPR-related jobs
- Open Agile-related jobs
- Open Threat detection-related jobs
- Open Open Source-related jobs
- Open OSCP-related jobs
- Open Intrusion detection-related jobs
- Open DevSecOps-related jobs
- Open Machine Learning-related jobs