Vultr - Senior CSIRT Engingeer
Requirements
• Minimum of 5 years experience in detection engineering, SIEM engineering, SOAR engineering, Security Operations, or a closely related role • Hands-on SIEM experience at an engineering level: rule authoring, parser development, log source integration, platform administration. • Experience building SOAR workflows and automated response playbooks. • Experience with EDR platforms, including policy configuration, telemetry analysis, and live response. • Demonstrated proficiency in PowerShell, Bash, Python, common Query Languages (FQL, KQL, EQL, LEQL, MQL, etc) and YARA, SIGMA, and CAPA rules. • Experience conducting security investigations, threat hunting, and incident response • Solid understanding of attack techniques and detection logic mapped to MITRE ATT&CK • Proficiency with Linux, MacOS, and Windows. • Experience with cloud infrastructure environments • Familiarity with data loss prevention concepts and insider threat detection patterns • Certifications such as BTL1, BTL2, CCD, CCSP, CKA, CKS, CJDE, CISSP, GCDA, GCED, GCFA, GCIH, GCIA, GCTD, GNFA, etc. • Experience in SOC2, ISO 27001, FedRAMP, or GDPR environments.
Responsibilities
• Engineer, tune, and maintain detection rules and analytics in the SIEM and EDR platforms • Administer SIEM platform health, parser configuration, log source onboarding, and data pipeline optimization. • Design and build SOAR playbooks and automated response workflows to streamline triage, enrichment, and containment. • Develop and maintain integrations between security tools (SIEM, EDR, SOAR, SEG, TIP, DLP, ticketing) • Map detection coverage to MITRE ATT&CK to identify and close gaps • Identify and drive improvements to security visibility across the environment, including new log sources, enrichment opportunities, and telemetry gaps • Assist with investigation of security events, from alert through remediation • Assist with conducting threat hunts across organizational telemetry • Assist incident response with log analysis, artifact collection, and containment • Manage EDR platform coverage, sensor health, and policy configuration • Coordinate with Threat Intelligence to translate intel into deployed, actionable detection logic • Coordinate with Security Engineering on infrastructure integrations and log pipeline architecture • Document detection logic, automation workflows, and operational procedures
Benefits
• $110,000 - $130,000 • Final compensation will vary depending on years of experience, background/skill set, location, and applicable laws. • INCLUSION & PRIVACY
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT