Detection and Response Engineer
Atlanta, GA
Applications have closed
Anduril Industries
Transforming US & allied military capabilities with advanced technology.WHAT YOU'LL DO
- Participate in on-call rotation responding to and triaging security events, performing security investigations, and incident analysis while effectively communicating findings to key stakeholders
- Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments
- Develop and optimize tailored detection signatures, response playbooks, and response automation using detection-as-code principles
- Develop and maintain large-scale data pipelines, ensuring reliability, timeliness, and accuracy of data being ingested across cloud, SaaS, enterprise, and product environments
- Participate in threat hunting initiatives, collaborating with various engineering and product teams to emit signals to incorporate into detections, new telemetry ingestion, and/or security controls
REQUIRED QUALIFICATIONS
- Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure
- Programming experience in one or more general purpose languages (Python, SQL, Go, etc)
- Experience building and refining SIEM tools, large-scale data pipelines, and logging architecture
- Experience investigating, responding to, and remediating incidents
- Experience in security monitoring, log analysis, and detection engineering within large data sets across endpoint, network, and a wide variety of application log sources
- Strong knowledge of attacker tactics, techniques, and procedures (TTPs)
- Strong communication skills and experience collaborating with internal and external stakeholders
- Must be able to obtain and hold a U.S. Top Secret security clearance
PREFERRED QUALIFICATIONS
- Experience working in a traditional software development lifecycle (i.e. Github, CI/CD, unit testing)
- Experience conducting incident response in the Cloud (AWS, Azure, GCP)
- Proficiency in AWS security controls and services
- Experience proactively threat hunting using threat intelligence to identify potential risks and weaknesses in telemetry
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation AWS Azure CI/CD Clearance Cloud GCP GitHub Incident response Log analysis Monitoring Python SaaS SDLC Security Clearance SIEM SQL Threat intelligence Top Secret TTPs
Perks/benefits: Career development Competitive pay Equity Health care Medical leave Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs