25 sep
|
Adp - Automatic Data Processing
|
Barcelona
25 sep
Adp - Automatic Data Processing
Barcelona
Overview
In this role you will design, implement and refine threat detection capabilities to protect ADP assets, collaborating with General Security and cross-functional teams. You will build and maintain cyber alert catalogs, leverage threat intelligence, and advance detection across SOAR, EDR, and NDR platforms. You will stay current on threats, contribute to playbooks and SOPs, and help automate detection and response processes. This position offers the opportunity to shape the security detections program and work with diverse tech and security teams to reduce risk and false positives.
Responsabilidades
- Develop advanced alerting capabilities based on threat intelligence, post-incident findings, new threats, and vulnerabilities
- Maintain an expert-level understanding of attacks, vectors, and emergent threats
- Develop new detection for the SOAR platform based on stakeholder requests, threat intelligence, threat hunting, or purple exercises
- Collaborate with CIRC and threat management to understand requirements
- Implement content in EDR, NDR, and SOAR
- Stay updated with latest threats and TTPs to integrate into detections
- Contribute to SOPs and provide content for reports, configuration guides, and training materials
- Work with CIRC, Threat management, and engineering to improve detections
- Analyze CIRC alert statistics to reduce false positives and focus engineering efforts
- Provide design support to improve detection and response capabilities
- Provide backup support to the CIRC team
- Mature CIRC playbooks, workflow automation, and use cases
- Build detection logic using security logs for high-fidelity detections
- Act as SME for security logs from Linux, macOS, Windows, EDR, NDR, and cloud
Requisitos principales
- 2 years+ experience in threat detection or threat hunting
- Strong analytical skills and cross-functional knowledge
- Strong interpersonal, verbal and written communication skills
- Strong knowledge of databases and data warehouse technologies
- Strong scripting experience in Python or PowerShell
- Experience building detection logic from security logs with high fidelity
- Strong project/program management experience
- Experience with one or more cloud providers (AWS or Azure)
- Familiar with log outputs from network/host devices (HIDS/NIDS, etc.)
- Proficiency with XML, HTML, Regular Expressions, JSON, REST, SQL
- Experience with SIEM and SOAR
- Creative thinker with problem-solving approach
- Ability to communicate security concepts to varied audiences
- High integrity and ability to work independently
- Strong communication skills
- Collaborative mindset
- Creative thinker
- Python
- SQL
- SOAR
📌 Detection Engineer (Barcelona)
🏢 Adp - Automatic Data Processing
📍 Barcelona