Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Responsibilities:
Developing and maintaining high-quality custom detection rules (Suricata/Snort/IDS/IPS).
Research and develop expertise for various threat surfaces and telemetry available for them.
Conducting code reviews and providing constructive feedback to ensure code quality and maintainability.
Debugging and fixing issues in existing detection/signature codebases.
Participate in the full software development life cycle, building well-designed, testable, efficient, secure code.
Work with team members to develop novel detections and continuously tune existing ones.
Understand the product and how Security Services delivers the service.
Propose coverage and efficacy improvements to the detection surface.
Build well-designed, testable, efficient, durable detections.
Build runbooks, reports, and supporting material for the detection surface.
Document research findings and share knowledge with the team and other departments.
Troubleshoot, educate, and share information with non-technical people.
Continuously learning and adopting best practices for code quality, software development methodologies, and programming principles to enhance coding skills and stay updated with industry advancements.
Requirements:
6 or more years of detection authoring experience with a focus on the following key areas: NDR/IPS/IDS detections/signatures, Development of anomaly and behavioral-based detections, and Tuning and optimization of detections.
Expertise on the inner workings of networking, protocols (TCP/IP, DNS, HTTP), protocol analysers, Suricata/snort rules, and other network-related threat management domain topics, e. g., LDAP, NTLM, etc.
Proven ability and experience to research and develop security detections related to network threat vectors.
Experience using MITRE ATT& CK, PCAP analysis, and threat intelligence feeds.
Experience with 3rd-party firewalls, IDS/IPS and network edge devices and their capabilities and configuration is a bonus, but minimally understanding their use and vulnerabilities.
We use and train a variety of technologies in MDR.
You should have a strong understanding of networking, protocols, and cybersecurity.
As a detection developer, you bring a strong knowledge base that you use to help the team solve complex technical and security problems.
Helpful to have experience in the following areas: SIEM detections, EDR detections/signatures, Sigma and Yara rules, Cloud security detections.
Experience in at least two of the following Development Languages and Methodologies: Python, Go, Java, or C/C++; Test-Driven Development, Full understanding and use of DevOps methods/tooling, Full understanding/application of secure development practices.
Cloud Development: AWS, Azure, and GCP using Kubernetes/Containers, IaaS, and key PaaS services; Agile (SCRUM/Kanban).
Experience in following security tooling is a plus: NGFW (PAN, CISCO, Fortinet, etc. ), Open Source IPS/IDS/NSM (e. g., Bro/Zeek/Suricata).
Experience
6-10 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.