Detection Engineer, Global Security Operations

hace 12 horas


San José, Costa Rica Splunk A tiempo completo

Join us as we pursue our innovative new vision to make machine data accessible, usable and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best experience for our customers. At Splunk, we’re committed to our work, customers, having fun and most importantly to each other’s success. Learn more about Splunk careers and how you can become a part of our journey

**Role**:
The Splunk Detection Engineer reports to the Senior Manager of Detection Engineering. In this role, you will be responsible for developing security content supporting the 24x7 monitoring operations and response to cybersecurity threats. You will have a deep understanding of Information Security principles and disciplines coupled with expert level knowledge of Splunk Processing Language (SPL), excellent development skills, and a continuous desire to learn and grow. We are a passionate team who has fun, enjoys a good laugh but above all else thinks security first.

**Responsibilities**:

- You will use your deep Splunk expertise in building detection use cases from scratch to identify cybersecurity threats
- Draw from your industry expertise in understanding how an attacker would behave and translate it to custom security detection content
- Engage with other teams to ensure detections are working as intended
- Identify and prioritize new data sources and their applicability to the detection of sophisticated adversaries
- Lead efforts to ensure data sources are aligned with Splunk’s Common Information Model (CIM)
- Drive complex initiatives with key business partners to continuously improve visibility
- Map security content to leading adversarial and defense technique ontologies (e.g. MITRE ATT&CK, D3FEND) and common control frameworks
- Understand & manage development backlog to ensure a steady stream of activities
- Conduct sprint reviews and celebration of successes for all items in the workstream.
- Collaborate across teams for training, development opportunities, and service improvement
- Capture development metrics in direct-support to executive-level briefings (daily, weekly, monthly)
- Ensure that all documents, workflows and processes remain accurate and up-to-date

**Requirements**:

- You have experience as a SOC Analyst, Security Content Developer and/or Security Engineer
- Advanced Splunk Enterprise Security experience
- Deep understanding of Splunk Data Models
- Ability to build and interpret SPL fluidly
- Coding proficiency in Python or equivalent language
- Knowledge of version control systems and automation capabilities within them, Gitlab, Bitbucket, Github, etc
- Ability to understand systems quickly, and translate understanding into logic to detect anomalies with the system
- You can lead people to think critically by guiding them without doing the work for them
- You have a passion for learning and a desire to enable the growth of others
- You possess a demonstrated ability to speak with people with varying knowledge in IT Security concepts and have the tailor your message to the audience
- You have an intimate understanding of Incident Response framework, root cause analysis, and analysis steps need to triage events
- Identifies opportunities for cycle-time reduction via automation or process enhancements
- Advanced knowledge of Cloud technologies in one or more leading cloud providers
- Ability and desire to break the norm and find creative scalable solutions to problems with the moxie to follow-through
- Excellent interpersonal skills and ability to see things through the customer’s eyes
- Tremendous attention to detail
- Bachelor’s degree in computer science, information security or related discipline is required or equivalent work experience



  • San José, San José, Costa Rica Equifax A tiempo completo

    About the RoleWe are seeking a highly skilled Cyber Cloud Detection Engineer to join our team at Equifax. As a key member of our cybersecurity team, you will be responsible for creating and implementing detection and prevention controls using a range of security tools (SIEM, DLP, IPS/IDS, EDR/Cloud). You will also manage and implement network and security...


  • San José, Costa Rica Equifax A tiempo completo

    **What you’ll do** - Create and implement detection and prevention controls using a range of security tools (SIEM, DLP, IPS/IDS, EDR/Cloud) - Management and implementation of network and security tools to support incident response - Implement controls to identify new attack TTPs and mitigation techniques in support of daily operations - Compile metrics and...


  • San José, San José, Costa Rica Equifax A tiempo completo

    About the RoleAt Equifax, we're looking for a skilled Cyber Threat Detection Engineer to join our team. As a key member of our security team, you'll be responsible for creating and implementing detection and prevention controls using a range of security tools (SIEM, DLP, IPS/IDS, EDR).Key Responsibilities- Develop and implement controls to identify new...


  • San José, San José, Costa Rica Equifax A tiempo completo

    About the Role: Equifax is seeking a highly skilled Advanced Cyber Security Specialist to join our team in Cyber Cloud Detection Engineer. This role will focus on creating and implementing detection and prevention controls using a range of security tools, managing network and security tools to support incident response, and developing use-case scenarios for...


  • San José, Costa Rica Equifax A tiempo completo

    Equifax is where you can power your possibly. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you. **What you’ll do** - Create and implement detection and prevention controls using a range of security tools (SIEM, DLP, IPS/IDS, EDR) -...


  • San José, San José, Costa Rica Boston Consulting Group A tiempo completo

    **Job Overview**Boston Consulting Group is seeking an experienced Data Security Engineer to join our global Information Protection team. This role will involve working in a Security Engineering, Architecture and Operations capacity to drive the evolution of our Secure Infrastructure Portfolio.Key Responsibilities:Spearhead security telemetry and...


  • San José, Costa Rica Microsoft A tiempo completo

    **Responsibilities**: **Qualifications**: **Required/Minimum Qualifications**: 5+ years of experience in software development lifecycle, large-scale computing, modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), and operations...


  • San José, Costa Rica Microsoft A tiempo completo

    Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end-to-end, simplified...


  • San Francisco, Heredia, Costa Rica Stryker A tiempo completo

    About the RoleAnalyze cybersecurity threats related to or unrelated to the medical industry and establish effective detection mechanisms. Collaborate with the incident response team to educate them on identified threats and their appropriate responses.Key ResponsibilitiesAnalyze security event data to identify patterns and trends that may indicate potential...


  • San José, Costa Rica Microsoft A tiempo completo

    Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end-to-end, simplified...

  • Cybersecurity Leader

    hace 2 semanas


    San José, San José, Costa Rica Microsoft A tiempo completo

    At Microsoft, we're committed to creating a safer digital world for everyone. Our Security Operations Lead will play a critical role in harnessing the power of our trillions of security signals to quickly identify and report the latest human adversary behaviors.The ideal candidate will have 5+ years of experience in software development lifecycle,...


  • San José, Costa Rica Boston Consulting Group A tiempo completo

    **WHAT YOU'LL DO**: Welcome to BCG Worldwide IT! We are seeking an IT Data Security Engineer to join our growing Information Protection team. You will be working in a Security Engineering, Architecture and Operations capacity to drive and support the continued evolution of our Secure Infrastructure Portfolio, notably in Data Security services providing...


  • San José, Costa Rica Splunk A tiempo completo

    Join us as we pursue our exciting new vision to make machine data accessible, usable and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best experience for our customers. At Splunk, we’re committed to our work, customers, having fun and most importantly to each other’s success. Learn...

  • Security Engineer

    hace 7 meses


    San José, Costa Rica Fragomen A tiempo completo

    Job Description A professional, who is passionate about security, capable of effecting change, and ready to take on new challenges, is what we seek. You will be joining a small team of Security Engineers who help make security a distinguishing factor in our immigration software and service offerings. An individual in this role would work closely with...


  • San José, Costa Rica Splunk A tiempo completo

    Splunk is here to build a safer and more resilient digital world. The world's leading enterprises use our unified security and observability platform to keep their digital systems secure and reliable. While customers love our technology, it's our people that make Splunk stand out as an amazing career destination and why we've won so many awards as a best...


  • San José, Costa Rica Boston Consulting Group A tiempo completo

    **WHAT YOU'LL DO**: BCG is looking to provide innovative and effective ways to secure and protect our users’ collaboration experiences. The security engineering chapter is newly established, and will be tasked with partnering with our SaaS and Sustaining Engineering teams, as well as our Solution Architecture team, to ensure that we are executing the...

  • Security Engineer 3

    hace 2 semanas


    San José, Costa Rica Oracle A tiempo completo

    Security Engineer 3-220000TF **Applicants are required to read, write, and speak the following languages**: English **Preferred Qualifications** OTA-RM-LAD-CR We are seeking a **Senior Security Engineer to join the Oracle+NetSuite Security team** responsible for securing systems, infrastructure, services, and data. We have mid and senior level positions...


  • San José, San José, Costa Rica Fragomen A tiempo completo

    About FragomenFragomen is a leading immigration services company that helps individuals and organizations navigate the complexities of global mobility.Job SummaryWe are seeking a highly skilled Chief Security Architect or Cloud Security Engineer Leader to join our team in Costa Rica. As a key member of our IT Security team, you will be responsible for...


  • San Francisco, Heredia, Costa Rica Stryker A tiempo completo

    Job OverviewStryker, a leading medical technology company, seeks an Information Security Specialist to join its team. This role is responsible for monitoring and responding to security incidents, managing security tools, and developing policies and procedures to ensure the protection of the organization's information data and assets.Key...


  • San José, San José, Costa Rica Sysdig A tiempo completo

    Sysdig is a leading provider of cloud-native threat detection solutions. We're passionate about delivering powerful security solutions to protect the cloud from source to run.We value diversity and open dialog to spur ideas, working closely together to achieve goals. As a remote-first company, we cultivate a strong culture across our teams. We strive to...