← Back to job listings
NG
Detection Engineer
NCC Group · Manchester, United Kingdom
About The Role
Join NCC Group as a Detection Engineer, where you will develop, maintain, and improve Splunk-based security detections across various platforms. You will analyze logs, create detections for cloud security monitoring, infrastructure security events, and bespoke assurance use cases. Additionally, you will review existing detection coverage, assess new log sources, and document detection purposes and logic. Support SOC analysts with alert context and investigation advice.
- Développer, maintenir et améliorer les détections de sécurité basées sur Splunk.
- Analyser les journaux provenant de diverses sources et créer des détections pour des domaines spécifiques.
- Examiner la couverture de détection existante, identifier les lacunes et évaluer de nouvelles sources de journaux.
- MITRE ATT&CK and common attacker behaviours
- Kubernetes or container security monitoring
- Security detection engineering, SIEM engineering, threat hunting, or security monitoring
- Splunk SPL or similar query language
- Candidates do not need to meet every requirement, but should have experience in some of the following:
- Regex and basic scripting, e.g. Python, Bash, or PowerShell
- Documentation using Jira, JSM, Confluence, or similar tools
- Cloud security concepts such as IAM, KMS, security groups, route tables, ACLs, object storage, and service accounts
- Cloud audit logs, especially AWS; GCP or OCI experience is also useful
- Use of allowlists, thresholds, baselines, aggregation, and anomaly-style detection logic
- Experience with Splunk Enterprise Security and Splunk Security Essentials
- Experience reviewing threat models, security testing outputs, or assurance requirements
- Experience writing or tuning scheduled alerts.
- Experience using a detection as code deployment pipeline
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring