Cyber Detection Engineer
Sofia, BG, 1407
We help the world run better
Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now!
We are looking for an SIEM Detection engineer with previous python exposure (or other programming scripting language), fluent in SPL or another query language.
The ideal candidate would have SOC L2/L3 background and the ability to contribute to the triage of the detection backlog.
The candidate should have a good understanding of entities and data models associated with various log types, a bonus for cloud workloads specific logs.
What you'll do
- Bring your experience or research a certain/new log source/sourcetypes.
- Understand how to document and differentiate a baseline (normal behavior) vs abnormal/low prevalence/outliers.
- Identify what information is needed given a log type and TTP. (what fields are relevant, what entities are involved, when and what enrichment is possible)
- Use your coding, data analytics and investigation skills to write new detection rules, tune existing correlation rules and build response capabilities mapped to MITRE ATT&CK and RE&CT
- Build automation and detection models to support identification of anomalous activity and response activities to mitigate threats at scale.
- Identify and consult on the design of countermeasures to mitigate threats in our environmen – be able to understand the audit policies and logging level (verbosity) and format of various security tools and select the settings tha enable just-enough-logging for the detection use-cases
- Coordinating with Security SMEs to build hunting rules and triggers, which focus on adversary activity within the cloud control plane and Linux servers
- Detection Rule testing and tuning to identify and reduce False-Positive & False-Negative
- Ensure that all documents, workflows and processes remain accurate and up-to-date
What you'll bring
- Ideally SOC experience in a datacenter environment (MSP)
- A good understanding of network security (cloud is a bonus)
- Experience working with endpoint telemetry/EDR security products preferred
- Technical proficiency on Linux
- Experience building dashboards and processes around use-case testing , versioning
- Security tool integration experience, familiarity with common information and log formats
- 5+ years of experience in Security including but not limited to: Threat Intel, Threat Detection, Cloud Security and or SOC experience
- Programming / scripting knowledge for automating day to day tasks – Splunk, Python, SQL, Powershell , bash
- Research mindset, with a hold on where to look for relevant information pertaining to cloud threats, vulnerabilities and key adversary’s modes of interest.
- An understanding of CI/CD, versioning tools, Jira/Kanban
Nice to have
- Familiarity with the Sigma project for security detection rule authoring.
- Advanced Splunk experience (or other SIEM equivalent)
- Infrastructure as code experience
- Knowledge of public cloud resources and control plane threats and vulnerabilities, and how it applies to MITRE ATTACK Framework.
- Platform knowledge around AWS, GCP and Azure, specifically around security configuration and monitoring.
- Experience with Threat Intel ingestion and generation
- Splunk ES certification, GIAC GMON, GCDA, GCTI, GCFE or other relevant certifications or projects experience
- Experience with BAS tools, commercial or open source.
#SAPECSCareers
We build breakthroughs together
SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together.
We win with inclusion
SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world.
SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com
For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training.
EOE AA M/F/Vet/Disability:
Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability.
Successful candidates might be required to undergo a background verification with an external vendor.
Requisition ID: 391472 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics Automation AWS Azure Bash CI/CD Cloud Data Analytics EDR ERP GCFE GCP GCTI GIAC Jira Kanban Linux MITRE ATT&CK Monitoring Network security Open Source PowerShell Python SAP Scripting SIEM SOC Splunk SQL Threat detection Vulnerabilities
Perks/benefits: Career development Flex hours Salary bonus Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Penetration Tester jobs
- Open Cloud Security Architect jobs
- Open Security Operations Engineer jobs
- Open Principal Security Engineer jobs
- Open Information Security Officer jobs
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Senior Product Security Engineer jobs
- Open Chief Information Security Officer jobs
- Open Cyber Security Architect jobs
- Open IT Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Staff Security Engineer jobs
- Open Cyber Security Specialist jobs
- Open Security Specialist jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Senior Network Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Security Consultant jobs
- Open IT Security Analyst jobs
- Open Senior Information Security Analyst jobs
- Open Security Operations Analyst jobs
- Open Manager Pentest H/F jobs
- Open Information Security Architect jobs
- Open Information System Security Officer jobs
- Open Agile-related jobs
- Open Risk assessment-related jobs
- Open SOC-related jobs
- Open Analytics-related jobs
- Open Network security-related jobs
- Open CISA-related jobs
- Open ISO 27001-related jobs
- Open GCP-related jobs
- Open IAM-related jobs
- Open Application security-related jobs
- Open Pentesting-related jobs
- Open Threat intelligence-related jobs
- Open Vulnerability management-related jobs
- Open DevOps-related jobs
- Open DoD-related jobs
- Open Security Clearance-related jobs
- Open APIs-related jobs
- Open CEH-related jobs
- Open Security assessment-related jobs
- Open SaaS-related jobs
- Open Malware-related jobs
- Open Kubernetes-related jobs
- Open Java-related jobs
- Open EDR-related jobs
- Open TS/SCI-related jobs