Senior Security Content Engineer
B
BlueVoyantCybersecurity
Remote, USFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 10+ years of experience in IT or cybersecurity, with a focus on SIEM and detection content.
- Required Skills
- PythonGitMicrosoft AzureRubyCI/CD
Requirements
- Bring expert experience writing detection signatures or algorithms.
- Analyze event logs and identify indicators of compromise at an expert level.
- Have hands-on experience with Microsoft Azure, Sentinel, Defender, and related tools.
- Work with Sentinel Incidents, Workbooks, Hunting Queries, and Notebooks.
- Use Kusto Query Language (KQL) or a similar language.
- Work with complex JSON data structures.
- Use development tools including Git, IDEs, and CI/CD pipelines.
- Have expert scripting skills in Python, Ruby, or similar languages.
- Bring experience in digital forensics and blue team operations.
- Understand network protocols and infrastructure at an expert level.
- Have knowledge of SIEM and SOAR platforms, API integrations, EDR, log analysis, malware detection, and network monitoring tools.
- Be familiar with case management systems, Atlassian Suite (Jira and Confluence), email security, DLP, encryption, and vulnerability management.
- 10+ years of experience in IT or cybersecurity focused on SIEM and detection content is listed as a nice-to-have.
- Have a bachelor's degree in a related field or equivalent professional experience and certifications; a relevant master's degree is preferred.
Responsibilities
- Enrich security signals to improve SOC efficiency and outcomes.
- Research threat actors and attack vectors to develop detection content for emerging threats.
- Design and build automation content for onboarding new products.
- Build complex detection analytic rules and improve detection capabilities.
- Help clients test and tune detection logic to reduce false positives and alert fatigue.
- Perform global tuning for complex alerts.
- Identify and promote reusable rules, automations, and dashboards across clients.
- Lead integration initiatives to optimize log ingestion and reduce noise.
- Deliver research-driven queries, signatures, rules, and knowledge base articles.
- Develop detection coverage for high-risk vulnerabilities and exploits.
View Full Description & ApplyYou'll be redirected to the employer's site