Senior Detection Engineer
Humana
Role tags
Tech stack mentioned
Role overview
Become a part of our caring community As a Senior Detection Engineer, you will be responsible for technical execution and delivery of Detection Engineering capabilities. This is an exciting opportunity to join an engineering focused security team that leverages automation and AI/ML capabilities with a cutting-edge detection-as-code CI/CD pipeline. This role has responsibility for delivering and curating custom threat detection content in Splunk, partnering closely with EIP groups such as Cyber Security Operations Centre (CSOC), Threat Hunting, Cyber Threat Intelligence, and IT teams such as Enterprise Observability to deliver threat detection services. This role will also lead and participate in defensive security projects and initiatives to defend Humana and its members against the evolving cybersecurity threat landscape. Skills - Develop custom tools and leverage automation and orchestration for threat detections, malware research and threat intelligence needs. - Strong familiarity of MITRE ATT&CK or similar frameworks. - Creation and maintenance of policy, standards, procedures, and documentation. - Use KPIs and other metrics to identify opportunities for process improvements. - Experience working under and providing support for regulatory frameworks such as HIPAA, PCI, SOC2, etc. You should be located within 50 miles of one of our Hub sites or be willing to relocate to one of these areas. These sites are in Atlanta GA, Boston MA, Charlotte NC, Chicago IL, Dallas TX, Ft. Lauderdale or Tampa FL, Louisville KY, Baltimore DC Metro, Nashville TN, or New York Metro NY. Use your skills to make an impact Required Qualifications - Bachelor's degree in Cybersecurity, Information Technology or a related field is preferred. - Minimum of 4 years' experience with threat hunting, threat research, threat intelligence or incident response. - Expert level understanding of the threat landscape in adversary tools such as command-and-control (C2) frameworks, remote management and access tools (RMMs), credential theft utilities, proxy and tunneling tools, cloud attack tooling, data exfiltration utilities, malware loaders, ransomware, and post-exploitation frameworks, as well as the tactics, techniques, and procedures (TTPs) associated with their use. - Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle, Elastic Stack, Rapid7, CrowdStrike NG-SIEM, Exabeam, Cortex, LogRhythm, IBM QRadar. - Deep understanding of how complex, multi-stage malware functions. - Advanced knowledge of security endpoint detection and response, network forensics and malware analysis across systems whether on premise or in varied cloud environments consisting of physical or virtual workloads. - Extensive experience creating and maintaining custom threat detection rules, leveraging enrichment data from threat intel and attack surface services. Preferred Qualifications - Professional certification in a relevant cybersecurity field (i.e., OSCP, GCTI, GREM, etc). Scheduled Weekly Hours Pay Range Description of Benefits About us Equal Opportunity Employer It is the policy of Humana not to discriminate against any employee or applicant for employment because of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or protected veteran status. It is also the policy of Humana to take affirmative action, in compliance with Section 503 of the Rehabilitation Act and VEVRAA, to employ and to advance in employment individuals with disability or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment. Originally posted on Himalayas