Senior Detection Engineer, Threat Detection & Monitoring (Remote)

Remote, USA Full-time
About the position The Senior Detection Engineer role will be responsible for the execution of the newly created, Business Application Security Monitoring (BASM) service. This is a technical role focused on extending AbbVie's Threat Detection and Monitoring (TDM) services to include business web applications. This role will serve as a technical subject matter expert on attacker tactics and techniques targeting web applications. This role will also coach junior team members, engage in advanced data analysis, work closely with the Incident Response teams (customer) and application owners. This position can be located anywhere in the U.S. This role involves creating threat detection content by collaborating with application owners to gain a better understanding of the application's design and implementation details. The detection rules will be implemented using application telemetry and logs available in the SIEM. Responsibilities • Onboarding new business application for security monitoring by following the application on-boarding process. • Ensuring application logs meet the minimum logging requirements to enable standard monitoring use-cases. • Collaborating with application SMEs to gain deeper understanding of application design and implementation, including identification of specific areas of security concern. • Performing data exploration and advanced data analysis to implement application-specific custom monitoring use-cases. • Executing the detection content lifecycle, including developing, analyzing, documenting, and maintaining detection content by following the TDM processes. • Fostering a collaborative relationship with business application SMEs during and following the application security monitoring enrollment. • Supporting and encouraging application teams to adopt enterprise SIEM to perform operational monitoring of their critical apps. • Lending technical expertise and helping coordinate defensive toolset engineering, including content creation, tuning, expansion of defensive platforms, and implementation of new controls. • Maintaining a solid command of various web application architectures and hosting platforms, including SaaS, IaaS, on-prem, dynamic and no-code/low-code workloads. • Collaborating with specialists and analysts to actively contribute to risk reduction efforts, including but not limited to assessments and in-depth research and analysis of threats. • Providing recommendations and influencing decisions made by leadership for improving program maturity. Requirements • Bachelors Degree and 7 years experience OR Masters Degree and 6 years experience OR PhD and 2 years experience of specialized information security experience. • Expertise in performing data analysis using a modern SIEM, including ability to interpret log data to infer application activity, user actions, and anomalies. • Ability to successfully interact with non-technical in-business contacts. • Strong business acumen and an ability to assess, understand, and articulate technical impact and risk to a diverse audience. • Deep knowledge of cloud hosting solutions and its use in web application development. • Strong knowledge of web application architectures, various hosting platforms, major operating systems, typical web application network protocols, systems administration, and web application security technologies. • In depth knowledge of key web application related concepts such as SAML, SSO, OAuth, MFA, SSL/TLS, etc. • Strong knowledge and application of cyber security terminology and concepts, and general understanding of the cyber threat landscape and attack vectors. • Thorough understanding of the MITRE ATT&CK framework and its practical applications. • Willingness to be available, as needed, for critical and major security issues. • Ability to author technical documentation and perform quality assurance reviews of documents created by peers. • Demonstrate critical thinking, problem-solving, and analytical skills; investigates, defines, and resolves critical issues. • Regularly collaborate with peers as well as business and IT stakeholders in support of daily activities. • Strong organization skills with attention to details. • Strong written and verbal communication skills with a high level of professionalism. • Ability to work independently and effectively as part of a team. • Ability to execute with limited guidance and contribute to decisions based on specialized knowledge. Benefits • Paid time off (vacation, holidays, sick) • Medical/dental/vision insurance • 401(k) to eligible employees • Short-term incentive programs • Long-term incentive programs Apply tot his job
Apply Now

Similar Jobs

Security Engineer - Detection & Response

Remote, USA Full-time

Staff Security Engineer Threat Detection and Response

Remote, USA Full-time

Threat Intelligence Analyst, Threat Defense

Remote, USA Full-time

Researcher - Online Threat Intelligence

Remote, USA Full-time

Sr. Intelligence Analyst - APAC Mission (Remote) USA - Remote

Remote, USA Full-time

Senior Manager, Threat Intelligence

Remote, USA Full-time

Protective Intelligence Analyst (Remote, East Coast US)

Remote, USA Full-time

Cybersecurity Threat Detection Engineer

Remote, USA Full-time

Third Shift Customer Solutions Representative (FULLY REMOTE)

Remote, USA Full-time

Senior Threat Detection Engineer (Remote)

Remote, USA Full-time

Experienced Customer Service Representative - Apple Home Advisor: Delivering Exceptional Support and Transforming Home Improvement Experiences

Remote, USA Full-time

Sourcing Specialist

Remote, USA Full-time

IT Consultant[Salesforce Developer] [Remote]

Remote, USA Full-time

Virtual Cybersecurity Trainee – Entry-Level

Remote, USA Full-time

Part- Time Cashier & Front End Team – Amazon Store

Remote, USA Full-time

Experienced TikTok Live Sales Operator and Content Creator for Beauty Products – Remote Work Opportunity with a Dynamic Beauty Brand

Remote, USA Full-time

**Experienced Data Entry Specialist – Remote Work Opportunity at arenaflex**

Remote, USA Full-time

Infection Prevention Strategist

Remote, USA Full-time

**Immediate Hiring: Customer Contact Center (Student Loan Advisor) at blithequark**

Remote, USA Full-time

ricerca: co-host per strutture airbnb

Remote, USA Full-time
Back to Home