Threat Detection Engineer

Reposted 4 Days Ago
Be an Early Applicant
Hiring Remotely in India
Remote
Junior
Cloud • Security • Cybersecurity
The Role
The Threat Detection Engineer manages customer onboarding in SIEM, automates alerting processes, modifies use cases, and ensures SIEM health.
Summary Generated by Built In
Description

DESCRIPTION
Proficio is an award-winning managed detection and response (MDR) services provider. We provide 24/7 security monitoring, investigation, alerting and response services to organizations in healthcare, financial services, manufacturing, retail and other industries. Proficio has been highlighted in Gartner’s Market Guide for Managed Detection and Response Services for the last three consecutive years. We have a track record of innovation. Proficio invented the concept of SOC-as-a-Service. We were the first MSSP to provide automated response services and the first in our space to provide a risk scoring dashboard.

 Our typical client is a medium to large-sized organization that lacks the in-house resources to address the challenges of a rapidly changing threat landscape. The difficulty of hiring and retaining cybersecurity professionals are widely understood but our prospective clients also struggle to effectively harness technology and build hardened processes.

 While Proficio has developed a unified service delivery platform designed to meet the needs of the most demanding clients, what sets us apart is the quality and passion of our people. We believe the SOC of the Future will meld the creativity of human intelligence with the power of advanced technologies like AI.

Summary

The Threat Detection Engineer will perform tasks to ensure the proper and timely on-boarding of new customers and products in the SIEM.  This role will work with other members of the team to identify, modify, customize, and apply use cases from our library, based on customer functionality and alerting requirements. Responsible for timely deployment of our services, works to automate the alerting process, provides reporting and dashboards, and coordinates with other internal departments to ensure continuous customer satisfaction.  The SIEM Content Engineer II is focused on SIEM health and troubleshooting; rule, report, and dashboard modification; and more intricate customer development requests. 

Responsibilities

  • Handle customer requests for development and promote applicable rules to the strategic team for base content inclusion.
  • Provide back-up support on SIEM onboarding tasks and collaborate with other teams (Security Analyst team) on required content.
  • Perform analysis and troubleshooting and other tasks to ensure overall SIEM health.
  • Modify rules, reports, and dashboards for internal and external use as necessary.
  • Process the more intricate use case development tickets from customer request queue.  This generally involves clarifying intent through internal resources to provide the most accurate response to our clients need.
  • Work closely with our Engineering, Analyst, and R&D teams to understand the company’s complete service offering in analyzing and resolving technical issues of our customers, thus create a better platform for our service delivery team.
  • Participate and perform other tasks as may be required for this role.
Requirements
  • Demonstrated knowledge of general networking principles including full knowledge of TCP/IP communication, the OSI model, common network ports, and basic network defense
  • Solid understanding of the threats reported by various data sources such as IDS/IPS, AV, HIDS/HIPS, WAFs, firewalls, and web proxies
  • Basic understanding of the current threat landscape including knowledge of different threat actor profiles and attack methods
  • Must be willing and able to complete trainings/certifications for self -improvement
  • Excellent communication and presentation skills within a team setting in a collaborative manner
  • Quick learner and intuitive thinker – the more you learn, the faster you’ll grow!
  • Effective documentation and time task management skills
  • Confidence in independently delivering effective technical solutions
  • Excellent problem-solving skill, ability to identify and apply appropriate technical resolutions
Benefits
  • Opportunity to work in a progressive organization with structured training and roadmap for success
  • Health benefits, lunches, gym reimbursement, and internet funding for our India staff!
  • Experience in one of the hottest IT industries today

Proficio is an EOE employer.

Proficio collects certain personal information upon your submission of an application for an open position. More information is available about your consumer rights and our privacy policy at 

Top Skills

Av
Firewalls
Hids/Hips
Ids/Ips
SIEM
Tcp/Ip
Wafs
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Carlsbad, CA
190 Employees
Year Founded: 2010

What We Do

Proficio is a world-class Managed Security Service Provider (MSSP) providing managed detection and response solutions, 24×7 security monitoring and advanced data breach prevention services to organizations globally.

Our rapid growth is being fueled by the rise in cloud-based services, the acceptance of the Software-as-a-Service (SaaS) model, and the increasing number of cyber security attacks on businesses, hospitals and government. We have developed proprietary security content and threat intelligence tools to identify and proactively defend against advanced attacks and insider threats. Proficio’s founders are veterans of the security and networking industry who have helped guide multiple companies to successful exits.

Proficio’s customers benefit from the most advanced security monitoring and 24×7 managed security services that until recently were outside the budget of all but the very largest enterprises. Proficio’s ProSOC service offerings include the following:
• 24×7 security event monitoring, alerting, and remediation
• Advanced SIEM correlation analysis
• Protection against complex attacks and insider threats
• Actionable intelligence that enables internal IT teams to effectively and quickly resolve issues
• Threat Intelligence
• Active Defense that blocks targeted attacks in real time 24×7
• Worry-free compliance audits for: PCI, HIPAA, SOX, GLBA, FFIEC, NERC CIP, and FISMA regulations
• Visibility to event logs with easy-to-use web portal, powerful reporting, dashboards, and drill-down analytics
• Full management of security devices including patching, health and performance monitoring, and tuning
• Free 12 month log retention
• Out-of-the-box support for 400+ log sources
• Scalable cloud-based deployment – fast implementation and no software or hardware purchases
• Advanced scanning eliminating vulnerabilities before they can be exploited

Similar Jobs

Cloudflare Logo Cloudflare

Specialist Solutions Engineer, Zero Trust

Cloud • Information Technology • Security • Software • Cybersecurity
Remote
Hybrid
2 Locations

Atlassian Logo Atlassian

Principal Product Security Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Remote
India

ServiceNow Logo ServiceNow

Sr Network Engineer

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote
Hybrid
Hyderabad, Telangana, IND
50K-100K

Rapid7 Logo Rapid7

NetSuite Admin/Engineer

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote
Hybrid
Pune, Maharashtra, IND

Similar Companies Hiring

Silverfort Thumbnail
Security • Sales • Information Technology • Cybersecurity • Automation
GB
442 Employees
RunPod Thumbnail
Software • Infrastructure as a Service (IaaS) • Cloud • Artificial Intelligence
Charlotte, North Carolina
62 Employees
Toro TMS Thumbnail
Transportation • Software • Sales • Enterprise Web • Cloud
Chicago, IL
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account