Lead Detection Engineer
This role is part of UKG's Global Security Detection Engineering team, responsible for detecting and responding to sophisticated cyber threats and attacks.
Responsibilities:
* Provide hands-on solutions, customization and tuning, automation, dashboards, and use case development for the SIEM, SOAR, and other stakeholder requirements.
* SUPPORT LEADING PRODUCTION LEVEL PROJECTS TO COMPLETION AS A CONTRIBUTOR AND A COLLABORATOR BETWEEN MULTIPLE STAKEHOLDER TEAMS.
* WORK ON A GLOBALLY DISTRIBUTED TEAM AND CREATE AND PRESENT STRATEGIES, TECHNICAL PLANS, AND ARCHITECTURES TO AUDIENCES OF TECHNICAL AND EXECUTIVE LEADERSHIP LEVELS.
* Maintain existing internal code, use cases, and further extend SIEM and SOAR integrations aligned to the Detection Engineering program efforts.
* Provide technical guidance and training to team members as needed.
Requirements:
* Extensive experience with security and hands-on technical automation experience, focused on creating use cases and detection-focused automation.
* Operational experience working directly with or in security operational teams including: SOC, Threat Intelligence, and Incident Response.
* Deep understanding of SOC, SIEM, and other engineering best practices, limitations, and ways of extending or customizing threat detection automation related use cases.
* Demonstrable hands-on skills in a major scripting/programming language or a search query language for use in security operations and threat detection.
* Experience with a major public cloud service provider (CSP) is preferred.
* Splunk Cloud ES and Splunk SOAR (Phantom) experience is highly preferred.
About UKG
UKG is proud to be an equal opportunity employer and is committed to promoting diversity and inclusion in the workplace, including the recruitment process.