Principal Detection Engineer

Posted Yesterday
Be an Early Applicant
Indianapolis, IN
Senior level
Information Technology • Consulting • Cybersecurity
At Pondurance, experts build cutting-edge security technology and work closely with customers to protect what matters.
The Role
As a Principal Detection Engineer, you will lead the development of threat detection capabilities, mentor junior engineers, and conduct research on emerging threats while collaborating with cybersecurity professionals to enhance security offerings.
Summary Generated by Built In

Principal Detection Engineer

REMOTE

 

About the Role: 

As a Principal Detection Engineer, you will play an integral role in developing and advancing our threat detection capabilities. You will be responsible for spearheading the identification of emerging threats and pioneering innovative detection methods to secure our clients' digital environments. As a leader, mentor, and innovator on our Detection Engineering team, you will act as an internal and external point of contact for escalations. 

You will have the opportunity to work on cutting-edge technologies and collaborate with a team of talented security professionals to drive innovation in the field of cybersecurity. Your deep expertise and strategic insight will be instrumental in elevating our cybersecurity offerings, ensuring our customers remain protected against the most sophisticated threats in an increasingly complex digital landscape.

 

Responsibilities:

  • Oversee and advise the deployment and tuning of security tools and technologies.
  • Check and suggest improvements to code, give feedback, and approve work by the detection engineering team.
  • Coach, mentor, and support junior detection engineers, ensuring timely and successful task completion and fostering an environment of continuous learning and improvement.
  • Regularly assess team projects, providing appropriate support, guidance, or training.
  • Build new alerting techniques and enhance existing alerts.
  • Conduct in-depth research and analysis of emerging cyber threats, attack vectors, and vulnerabilities to proactively identify potential risks.
  • Stay current with the latest threat landscape and integrate threat intelligence data into detection mechanisms.
  • Collaborate with SOC management and analysts to improve alerting workflow.
  • Improve efficacy of telemetry collection and threat detection rules. 
  • Foster cross functional relationships with other department engineers to align goals and transfer knowledge.
  • Help create documents, reports, technical advisories, and whitepapers for internal and external stakeholders.
  • Participate in sprint demo/planning and other team or project meetings.

 

Technologies: 

  • Expert SIEM / SOAR Knowledge: Be able to effectively use SIEM / SOAR platforms to build queries, alerts, actions, etc.
  • Advanced Data Query Experience: Must be able to write and transform queries from one language to another
  • Advanced Windows Experience: Logging / Log Analysis / Log Alerting 
  • Intermediate Linux Experience: Must know how to operate on a Linux CLI
  • Cloud Application Logs & Monitoring: Familiarity with AWS, Azure, GCP, and O365 is a plus
  • Ticketing & Collaboration Tools: Efficiently utilize internal ticket queues and development management platforms (Atlassian JIRA/Confluence experience a plus)
  • Programming: Experience with programming in Python is a plus

 

Knowledge and Skills: 

  • Bachelor's degree in Computer Science, Engineering, related field, or equivalent work experience
  • 7+ years of experience in threat detection 
  • Certifications such as CISSP, CEH, OSCP, Security+, GIAC or equivalent are a plus.
  • Expert knowledge of network protocols, operating systems and security technologies.
  • Strong understanding of threat landscapes, threat intelligence, and threat hunting methodologies. 
  • Experience with tools used for threat hunting and knowledge of various attack vectors
  • Strong understanding of cyber threats, attack methodologies, and vulnerability assessment.
  • Significant experience with Security Information and Event Management (SIEM) systems
  • Excellent communication and collaboration skills, with the ability to work effectively in a team environment
  • Analytical Thinking: Break down the fundamental components of a problem or situation, examine the relationship between them, verify all pertinent facts and draw an appropriate conclusion.
  • Applied Technical Thinking: Able to apply specialized, theoretical knowledge to efficient operational uses.
  • Multitasking: Able to multitask effectively and shift focus easily and rapidly from one task to another.

Top Skills

Python
The Company
HQ: Indianapolis, IN
128 Employees
Remote Workplace
Year Founded: 2008

What We Do

Pondurance delivers world-class Managed Detection & Response (MDR), Incident Response (IR), Vulnerability Management, and Advisory Services to industries facing today’s most pressing and dynamic cybersecurity challenges. Our U.S. based Security Operations Center (SOC) offers personal, proactive, and around-the-clock cybersecurity to protect the human experience. We take a risk-based approach to cybersecurity; so you know you are protecting your most valuable assets and reducing your cyber risk.

Our mission is to ensure that every organization is able to detect and respond to cyber threats – regardless of size, industry or current in-house capabilities. We believe AI and automation alone aren’t enough, you need ingenious human experience because attackers aren’t machines, they are people. We combine our advanced platform with decades of human intelligence to speed detection and response and contain cybersecurity threats quickly to ultimately decrease risk to your mission.

Why Work With Us

At Pondurance we embrace, educate, and protect people by helping make our world a better and safer place. We believe in inviting good people into our company who are driven to become great! Every person at Pondurance is encouraged to focus and grow in their individual areas of interest, passion, and career path.

Gallery

Gallery

Similar Jobs

Cox Enterprises Logo Cox Enterprises

Senior Lead Cloud Architect - AWS (RapidScale)

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
Indianapolis, IN, USA
50000 Employees
142K-237K Annually

Cox Enterprises Logo Cox Enterprises

Senior Lead Cloud Architect - GCP (RapidScale)

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
Indianapolis, IN, USA
50000 Employees
142K-237K Annually

Cox Enterprises Logo Cox Enterprises

Senior Lead Cloud Architect - Azure (RapidScale)

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
Indianapolis, IN, USA
50000 Employees
142K-237K Annually

PwC Logo PwC

Managed Services - Engineering Operations - Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
Indianapolis, IN, USA
364000 Employees
58K-161K Annually

Similar Companies Hiring

Jobba Trade Technologies, Inc. Thumbnail
Software • Professional Services • Productivity • Information Technology • Cloud
Chicago, IL
45 Employees
InCommodities Thumbnail
Renewable Energy • Machine Learning • Information Technology • Energy • Automation • Analytics
Austin, TX
234 Employees
HERE Thumbnail
Software • Logistics • Information Technology
Amsterdam, NL
9000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account