14h ago
Detection Engineer
Remote - United States
$124k-$155k / year
full-timemid Remotehealthcare
๐ Tech Stack
๐ผ About This Role
You'll design, build, and improve detection capabilities across our security stack for a healthcare data collaboration platform. You will play a critical role in identifying threats, reducing risk, and enabling rapid response through high-fidelity detections and strong collaboration with Security Operations and Incident Response teams. This role stands out for leveraging Cyberhaven to build data exfiltration and insider risk detections.
๐ฏ What You'll Do
- Design, develop, and maintain detection logic across endpoint, network, and cloud environments
- Create and tune detections using CrowdStrike, Zscaler, SIEM, and DLP solutions
- Leverage Cyberhaven to build data exfiltration and insider risk detections
- Analyze logs and telemetry to identify attack patterns and anomalies
๐ Requirements
- Strong experience with Data Loss Prevention (DLP) tools like CyberHaven and Microsoft Purview
- Experience with CrowdStrike and Zscaler (or comparable EDR and network security platforms)
- Deep understanding of Windows event logs and investigation-relevant artifacts
- Experience with SIEM platforms, log management systems, and endpoint security tools
โจ Nice to Have
- Experience building detections mapped to frameworks such as MITRE ATT&CK
- Familiarity with scripting or query languages (e.g., Python, KQL, SPL, SQL)
- Experience with insider threat or data exfiltration detection strategies
๐ Benefits & Perks
- ๐ฐ Competitive compensation ($124k-$155k USD)
- ๐ฅ Health insurance (implied)
- ๐ป Remote work
- ๐ Vaccination requirements (flu, Tdap, COVID-19) - exemptions possible
๐จ Hiring Process
Estimated timeline: 3-5 weeks ยท AI estimate
- 1Application Reviewยท 1 week
- 2Recruiter Phone Screenยท 30 min
- 3Technical Interviewยท 1 hour
- 4Hiring Manager Interviewยท 45 min
- 5Offerยท 1 week
0 0 0