Detection Engineer
AI in this role
Key Responsibilities
- Schedule and host threat workshops utilizing industry-approved methodologies such as DREAD or STRIDE.
- Correlate log events in SIEM solutions with activities which have taken place in the (business) application or technology.
- Query data ingested into customer SIEM environments to assess the practical feasibility of newly proposed detections.
- Prepare pseudo-logic and work packages for detection engineers who write detections-as-code within the NCC detection repository.
- Derive new generic detection opportunities from Threat Intelligence reports to further expand NCC’s detection library.
- Identify potential abuse patterns in customer applications.
- Query large datasets of data in SIEMs (Sentinel & Splunk).
- Explain (potential) attack paths to customers.
- Write pseudo-logic for the development of new detections.
- Track the status of detections under development and share status updates with the customer.
- Obtain feedback from customers on exceptions and allowed behavior during the testing phase of the development of new analytics.
- Ensure work is up-to-date and tracked in (internal) ticketing system(s).
Skills, Knowledge & Expertise
- Experience in detection engineering on a range of technologies (SIEM and EDR)
- OR
- Experience in SOC or Managed Detection Services
- OR
- Experience in Analytically-minded IT Systems administration/Network Administration and looking for a change in career/focus on Security
- Excellent oral and written communication skills.
- Ability to work with client engagement teams and NCC colleagues to continuously improve the service we deliver.
- Good understanding of IT Systems and platforms from a security context.
- A security mindset and demonstrable experience or knowledge of contemporary attack tactics and techniques.
- Forensics or Incident Response competency would be considered valuable.
- Strong knowledge of the latest threats in security.
- The skills to translate technical attacks to effects in the business (and vice versa).
- Experience in simulating attacks is considered an advantageous skill to enhance other skills
- Experience with SIEM tools, preferably Splunk and Microsoft Sentinel.
And has knowledge of one or more of the below:
- Azure or other cloud technologies,
- Windows Active Directory,
- Windows Operating System fundamentals,
- Networking fundamentals.
- System management technologies
- Identity and access management procedures and technologies
How we rate this
Detection Engineer at NCC Group rates 35 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Classification
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Get new AI jobs by email
One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles that involve little AI, at other companies.
$183k-$340kUnited States of America, Washington, District of Columbiajust now
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step