In-depth knowledge of external attacks and detection techniques to be able to run analysis of the requirements provided by threat intelligence / SOC teams, generate list of rules that could be implemented (based on self analysis of a threat and avaiable log sources), work with SOC team to operationalize and Purple Team to test..
Familiarity with MITRE ATT&CK framework and Tactics, Techniques, and Procedures (TTPs).
Experience with security tools such as Splunk, MDE , Databricks to be able to write custom detections to detect various threats (preferably MDE)
Preferred candidate profile
Job Classification
Industry: IT Services & Consulting Functional Area / Department: IT & Information Security Role Category: IT Security Role: Application Security Engineer Employement Type: Full time