Threat Detection Engineer developing detection rules in Google SecOps for cybersecurity startup. Collaborating with Security Operations team to enhance security posture against threats.
Responsibilities
Design, develop, implement, and maintain custom detection rules, correlation searches, and alerts within Google Security Operations (SecOps) to identify malicious activity, security incidents, and policy violations.
Utilize your expertise in the SecOps detection engine and YARA-L syntax to create efficient and effective detection logic.
Analyze large datasets of security logs and events from various sources (e.g., cloud platforms, endpoint detection and response (EDR), network devices, applications) to identify patterns and anomalies indicative of threats.
Stay up-to-date with the latest threat intelligence, attack techniques, and security trends to proactively develop new detection strategies.
Collaborate closely with Security Analysts to tune detections logic based on incident analysis and threat landscape changes.
Contribute to the development and maintenance of security documentation, including YARA-L rules, response strategies, playbooks, and operational procedures.
Participate in the evaluation and integration of new security tools and technologies.
Automate detection creation, threat intelligence gathering, and rule deployment.
Provide mentorship, training, and guidance to junior team members.
Requirements
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical experience).
Minimum of 5 years of experience in a security operations role, with a strong focus on threat detection and analysis.
Proven experience developing and implementing YARA-L rules within Google Security Operations (SecOps) is essential.
Experience with threat intelligence and its integration into detection strategies.
Deep understanding of security principles, common attack vectors, and threat actor tactics, techniques, and procedures (TTPs).
Strong analytical and problem-solving skills with the ability to analyze complex security logs and identify meaningful patterns.
Proficiency in scripting languages such as Python or similar for automation and analysis.
Experience working with various security technologies and data sources, including but not limited to:
Cloud security platforms (e.g., GCP, AWS, Azure)
Endpoint Detection and Response (EDR) solutions
Security Information and Event Management (SIEM) systems
Manage engineering processes for the design and service of Lincoln Electric Automation equipment. Lead teams in the creation of control and robot programs while adhering to project timelines and budgets.
AEI / OT Engineer optimizing and securing industrial systems at DSM - Firmenich. Working hands - on to improve and maintain a reliable OT environment in a production factory.
Providing technical support and troubleshooting for Veeam Backup and Replication solutions within the Technical Customer Support team, ensuring customer satisfaction and effective issue resolution.
Senior Middleware Development Engineer at Intel designing next - gen communication libraries for high - performance computing. Collaborating with teams to optimize software for scientific computing and AI systems.
Chassis Driveline Engineer supporting design, development, and validation of driveline systems for Hyundai vehicles. Collaborating with cross - functional teams to ensure reliability and performance.
Engenheiro(a) Eletrotécnico na Gewiss, realizando instalação e manutenção de equipamentos elétricos. Trabalhando em um ambiente dinâmico, voltado para inovação em automação residencial.
R&D Engineer developing new products and optimizing production processes at Bridgestone in Stargard, Poland. Involves teamwork and continuous improvement initiatives.
Controls Engineer designing and optimizing automated medical waste processing systems at Daniels Health. Seeking experienced candidates with a strong background in PLCs, robotics, and machine vision.
Identity and Access Management Engineer at Specsavers delivering exceptional value through identity services and integrating applications. Collaborating with global teams to enhance access and security.