14h ago

Detection Engineer

Remote - United States

$124k-$155k / year

full-timemid Remotehealthcare

๐Ÿ›  Tech Stack

๐Ÿ’ผ About This Role

You'll design, build, and improve detection capabilities across our security stack for a healthcare data collaboration platform. You will play a critical role in identifying threats, reducing risk, and enabling rapid response through high-fidelity detections and strong collaboration with Security Operations and Incident Response teams. This role stands out for leveraging Cyberhaven to build data exfiltration and insider risk detections.

๐ŸŽฏ What You'll Do

  • Design, develop, and maintain detection logic across endpoint, network, and cloud environments
  • Create and tune detections using CrowdStrike, Zscaler, SIEM, and DLP solutions
  • Leverage Cyberhaven to build data exfiltration and insider risk detections
  • Analyze logs and telemetry to identify attack patterns and anomalies

๐Ÿ“‹ Requirements

  • Strong experience with Data Loss Prevention (DLP) tools like CyberHaven and Microsoft Purview
  • Experience with CrowdStrike and Zscaler (or comparable EDR and network security platforms)
  • Deep understanding of Windows event logs and investigation-relevant artifacts
  • Experience with SIEM platforms, log management systems, and endpoint security tools

โœจ Nice to Have

  • Experience building detections mapped to frameworks such as MITRE ATT&CK
  • Familiarity with scripting or query languages (e.g., Python, KQL, SPL, SQL)
  • Experience with insider threat or data exfiltration detection strategies

๐ŸŽ Benefits & Perks

  • ๐Ÿ’ฐ Competitive compensation ($124k-$155k USD)
  • ๐Ÿฅ Health insurance (implied)
  • ๐Ÿ’ป Remote work
  • ๐Ÿ’‰ Vaccination requirements (flu, Tdap, COVID-19) - exemptions possible

๐Ÿ“จ Hiring Process

Estimated timeline: 3-5 weeks ยท AI estimate

  1. 1Application Reviewยท 1 week
  2. 2Recruiter Phone Screenยท 30 min
  3. 3Technical Interviewยท 1 hour
  4. 4Hiring Manager Interviewยท 45 min
  5. 5Offerยท 1 week
0 0 0