Senior Security Content Engineer

B
BlueVoyantCybersecurity
Remote, USFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
10+ years of experience in IT or cybersecurity, with a focus on SIEM and detection content.
Required Skills
PythonGitMicrosoft AzureRubyCI/CD

Requirements

  • Bring expert experience writing detection signatures or algorithms.
  • Analyze event logs and identify indicators of compromise at an expert level.
  • Have hands-on experience with Microsoft Azure, Sentinel, Defender, and related tools.
  • Work with Sentinel Incidents, Workbooks, Hunting Queries, and Notebooks.
  • Use Kusto Query Language (KQL) or a similar language.
  • Work with complex JSON data structures.
  • Use development tools including Git, IDEs, and CI/CD pipelines.
  • Have expert scripting skills in Python, Ruby, or similar languages.
  • Bring experience in digital forensics and blue team operations.
  • Understand network protocols and infrastructure at an expert level.
  • Have knowledge of SIEM and SOAR platforms, API integrations, EDR, log analysis, malware detection, and network monitoring tools.
  • Be familiar with case management systems, Atlassian Suite (Jira and Confluence), email security, DLP, encryption, and vulnerability management.
  • 10+ years of experience in IT or cybersecurity focused on SIEM and detection content is listed as a nice-to-have.
  • Have a bachelor's degree in a related field or equivalent professional experience and certifications; a relevant master's degree is preferred.

Responsibilities

  • Enrich security signals to improve SOC efficiency and outcomes.
  • Research threat actors and attack vectors to develop detection content for emerging threats.
  • Design and build automation content for onboarding new products.
  • Build complex detection analytic rules and improve detection capabilities.
  • Help clients test and tune detection logic to reduce false positives and alert fatigue.
  • Perform global tuning for complex alerts.
  • Identify and promote reusable rules, automations, and dashboards across clients.
  • Lead integration initiatives to optimize log ingestion and reduce noise.
  • Deliver research-driven queries, signatures, rules, and knowledge base articles.
  • Develop detection coverage for high-risk vulnerabilities and exploits.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now