Cyber Defense Engineer
Join a cyber defense operations team protecting enterprise infrastructure and customer-facing products. Monitor and investigate security events, respond to incidents, improve detection coverage, and use AI-assisted tools to support security workflows.
Responsabilidades
- Monitor and triage alerts across SIEM, EDR, and CSPM platforms for corporate and product environments.
- Investigate security alerts, assess scope and severity, and escalate when needed.
- Use AI-assisted tools for triage, enrichment, and investigation.
- Track alerts through their lifecycle and document findings in ticketing and case management systems.
- Participate in incident response from detection through remediation, including evidence collection, forensic analysis, root cause analysis, and stakeholder communication.
- Investigate SIEM, endpoint, cloud, identity, and network data sources and execute incident response runbooks.
- Maintain evidence handling and chain-of-custody procedures.
- Prepare incident summaries and post-incident reports.
- Design, implement, and tune SIEM and EDR detection rules; reduce false positives and address coverage gaps.
- Translate threat intelligence into detection content and maintain coverage mapped to MITRE ATT&CK.
- Validate detection logic through hypothesis-driven threat hunts.
- Evaluate and improve AI and automation capabilities, including prompts, agent workflows, and LLM-based pipelines.
- Partner with engineering teams on log ingestion, data quality, and tool integrations.
- Maintain shift handoffs, operational notes, runbooks, playbooks, and standard procedures.
- Participate in an on-call rotation, tabletop exercises, purple team activities, and post-incident reviews.
- Track operational security metrics and identify improvements.
Requisitos
- At least 2 years of experience in a SOC, security operations, or incident response role.
- Understanding of MITRE ATT&CK, network protocols, and endpoint behavior.
- Experience with at least one SIEM platform and familiarity with search or detection queries.
- Familiarity with EDR platforms and cloud environments; IaaS experience preferred.
- Comfort using AI systems in security workflows.
- Strong written communication skills for technical and non-technical audiences.
Se valora
- Experience leading complex incident response engagements.
- Experience with identity and access management platforms and cloud security posture management tools.
- Scripting or automation skills applied to security workflows.
- Familiarity with SOAR or orchestration tools.
- Experience with AI agent architectures, LLM-based automation, or prompt engineering for security.
- Experience with threat intelligence programs or detection-as-code pipelines.
- Knowledge of privileged access management and related threat actors.
- Experience evaluating emerging technologies in production security environments.