Threat Detection Engineer

Posted Yesterday
Be an Early Applicant
Salt Lake City, UT, USA
In-Office
Mid level
Information Technology • Security • Cybersecurity
The Role
Support detection engineering by creating and tuning SIEM rules, reviewing logs, maintaining documentation, collaborating with SOC analysts, updating use cases, producing detection metrics, and contributing to detection-as-code projects.
Summary Generated by Built In

Threat Detection Engineer 

 

Who We Are 

Legato Security is an information security firm founded upon the belief that every organization has the right to keep its data private and secure. Our mission is to build close partnerships with our clients, serving them not as just a vendor, but as trusted advisors helping to build effective, proactive plans. Our focus is always on both the technical and human elements within an organization. We believe in comprehensive strategies designed to harden networks, deflect attackers, and rapidly recover from any accidents. As technology progresses, so do our tactics, ensuring our experts are always prepared to serve forward-looking leaders eager to stay ahead of emerging threats. 

 

Position Overview 

Legato Security is seeking a motivated junior or mid-level Detection Engineer to assist with detection engineering efforts. As a Detection Engineer, you will assist with rule creation, rule tuning, creating documentation, assisting with on-going infrastructure projects, and assisting with customer requests.

Specific Job Responsibilities 

  • Create, improve, review, and tune detection rules in various SIEMs (e.g., Sumo Logic, Google SecOps, Stellar Cyber). This will include log reviews of customer environments to make informed decisions.
  • Assist in creating and maintaining documentation for detection procedures, workflows, and active projects.
  • Collaborate with SOC analysts to improve detection accuracy and reduce false positives
  • Help maintain and update detection use cases based on emerging threats and customer-specific logs.
  • Assist in creating regular reports on detection metrics and effectiveness.
  • Review and respond to internal and customer requests to assist with anything related to detection engineering.
  • Contribute to declarative and imperative programming projects to assist with detection as code.

 Qualifications 

Required Qualifications: 

  • Bachelor's degree in Computer Science, Cybersecurity, related field or equivalent industry experience
  • 3-5 years of experience in detection engineering or a related field (e.g., SOC Analyst, Pen Testing, IT Infrastructure, Network Engineering, or Software Development). Job-specific experience in detection engineering is not required
  • Familiarity with networking principals (e.g. routing, common protocols, firewall functionality, etc.)
  • Basic understanding of Windows operating systems (e.g. versions, common exploits, understanding of registries, exposed protocols, common enumeration commands, etc.)
  • Active Directory Fundamentals (e.g. basic understanding of NTLM and Kerberos, how to use LDAP, understanding of common attacks within Active Directory.)
  • Understanding of Detection as Code and common exploits
  • Strong interest in pursuing a career in detection engineering
  • Ability to quickly learn different tool sets and environments
  • Strong written and verbal communication skills
  • Ability to prioritize multiple competing projects, meet deadlines, and work effectively in a team environment

Preferred Qualifications: 

  • Applicants who demonstrate personal learning and curiosity through personal projects will be prioritized. e.g. home labs, personal Github projects, write-ups, blog posts, Hack the Box profile, TryHackMe profile.
  • Relevant certifications such as OSCP (Offsec), OSDA (Offsec), CPTS (HTB), CDSA (HTB), etc.

Perks 

·       Start-up company in a growth phase with opportunity for advancement based on performance 

·       Start-up culture with an office in downtown Salt Lake City, UT 

·       Competitive medical and dental benefits for employee and family members 

·       Other voluntary benefits such as short-term disability, life insurance, children’s orthodontia, with additional voluntary benefits available 

·       Flexible Paid Time Off policy 

·       Professional Development opportunities specific to role  

 

Skills Required

  • Bachelor's degree in Computer Science, Cybersecurity, related field or equivalent industry experience
  • 3-5 years of experience in detection engineering or a related field (SOC Analyst, Pen Testing, IT Infrastructure, Network Engineering, Software Development)
  • Familiarity with networking principles (routing, common protocols, firewall functionality)
  • Basic understanding of Windows operating systems (versions, common exploits, registries, exposed protocols, enumeration commands)
  • Active Directory fundamentals (NTLM, Kerberos, LDAP, common AD attacks)
  • Understanding of Detection as Code and common exploits
  • Strong interest in pursuing a career in detection engineering
  • Ability to quickly learn different tool sets and environments
  • Strong written and verbal communication skills
  • Ability to prioritize multiple competing projects, meet deadlines, and work effectively in a team environment
  • Personal learning and curiosity demonstrated via home labs, GitHub projects, write-ups, Hack The Box or TryHackMe profiles
  • Relevant certifications (e.g., OSCP, OSDA, CPTS, CDSA)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Salt Lake City, Utah
86 Employees
Year Founded: 2020

What We Do

Our mission is to provide comprehensive, customer-centric managed cyber security services that effectively manage and mitigate cyber risks on behalf of our customers. We continually adapt and innovate our services to stay ahead of emerging threats and evolving technologies, delivering peace of mind and enabling our customers to focus on their core business objectives. With a team of dedicated experts and cutting-edge technologies, we strive to build trusted partnerships, deliver exceptional value, and safeguard our customers' digital assets with unwavering commitment.

Similar Jobs

Samsara Logo Samsara

Technical Support

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
133K-213K Annually

Gusto Logo Gusto

Consultant

Fintech • HR Tech
Easy Apply
Remote or Hybrid
United States
4405 Employees
98K-140K Annually

PwC Logo PwC

Financial Services Tax - Real Estate Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
65 Locations
370000 Employees
77K-214K Annually

DraftKings Logo DraftKings

Lead Product Designer

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
148K-185K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account