A Security Developer has a clear history of successful contributions to professional detection development projects. They are driven, curious, and results-oriented. They can manage competing priorities as they relate to improving our existing codebase of detections and constantly challenge the status quo. With additional experience and exposure to advanced detection development patterns and projects, they are capable of becoming a Senior Security Developer within 2 years.
You'll be working as a detection developer on our Detection Operations Team, responsible for ensuring the quality and scale of our detection base and presenting actionable detections to our Security Services teams and :
- Providing mentorship and technical leadership to the team.
- Developing and maintaining Python and YAML-based detections, software, and systems.
- Research and develop expertise in the various threat surfaces and telemetry available for them.
- Propose coverage and efficacy improvements to the detection surface.
- Work with team members to develop novel detections and continuously tune existing ones.
- Build runbooks, reports, and supporting material for detection surfaces.
- Collaborating with cross-functional teams to gather requirements and implement detections.
- Writing clean, efficient, and reusable code in Python.
- Conducting code reviews and providing constructive feedback to ensure code quality and Debugging and fixing issues in existing Python codebases.
Requirements :
2 or more years of professional experience as a Detection Developer.Experience consists of projects contributing in either Python or YAML OS Specific Telemetry (Windows Security / Sysmon logs, Linux), Windows PowerShell Monitoring, SIEM Detections, EDR detections / signatures, Sigma, and Yara Rules.Development of anomaly and behavioral-based detections.Tuning and optimization of detections for all the above.Professional certifications in Security and / or Cloud are desired (i. e. CISSP, GNFA, GCFA, GCFE, GREM).Experience leading Agile development teams, preferably with formal Agile training.(ref : hirist.tech)