
Senior SOC Detection Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Georgia.
• Take ownership of the entire lifecycle of security detections, including researching attack techniques, defining logging requirements, and developing, testing, deploying, and continuously enhancing detection content in Splunk.
• Create, test, deploy, and sustain detection and correlation rules in Splunk or a comparable SIEM.
• Convert incident investigations, threat hunting, and attack research into efficient detections.
• Examine false positives, false negatives, and gaps in detection.
• Enhance detection coverage and align detections with MITRE ATT&CK techniques.
• Develop and refine SPL queries, dashboards, reports, and risk-based detections.
• Establish requirements for logging, parsing, normalization, enrichment, and data quality.
• Create monitoring and health checks for detection rules and data sources.
• Participate in automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.
• Engage in incident investigations, threat hunting, purple team exercises, and attack emulation.
• Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.
• Document detection logic, data sources, dependencies, limitations, and expected behaviors.
• Enhance the organization’s capacity to recognize, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments.
• Solid hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related discipline.
• Profound understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.
• Strong expertise in Splunk SPL or another enterprise SIEM platform.
• Experience in developing complex queries, correlations, dashboards, and reports.
• Practical experience in tuning detections and managing exceptions and allowlists.
• Ability to define and assess logging and telemetry requirements.
• Proficiency in Python, PowerShell, or Bash for automation tasks.
• Familiarity with Git, code reviews, APIs, and fundamental CI/CD practices.
• Understanding of Windows and Linux security monitoring.
• Capability to independently investigate complex issues and drive solutions to completion.
• Strong communication skills and the ability to collaborate effectively across teams.
• Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.
• Familiarity with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.
• Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.
• Experience in building detection quality metrics and automated validation frameworks.
• Familiarity with Terraform, Ansible, or other infrastructure-as-code tools.
• Involvement in security research, conferences, or the broader security community.
• Private health insurance.
• Sports benefits.
• Comprehensive Mental Health Program.
• Free English lessons (online).
• Local language courses.
• Paid time off.
• Maternity leave support.
• Referral program rewards.
• Opportunities for upskilling, internal workshops, and participation in professional conferences and corporate events.
Mercor
RTX
ICF
HETI
Get handpicked remote jobs straight to your inbox weekly.