Required Skills: Splunk, SPL, Python scripting, AWS security logs
Job Description
T Security Engineer IV - DFIR & Detection
Additional Details/Notes: Hiring manager is specifically seeking a hands-on Security Engineer with a combination of Detection Engineering AND Digital Forensics / Incident Response (DFIR). Please do not submit candidates whose experience is primarily security tool implementation/deployment, SOC alert monitoring, security administration, or project management. The role is approximately 50% DFIR / advanced incident investigation and 50% detection engineering. Target is 4+ years of relevant security experience with demonstrated hands-on work across both areas.
CORE REQUIREMENTS:
• Detection Engineering: Must have experience personally building, tuning, or improving security detections. Candidates who have only investigated pre-built alerts are not sufficient.
• DFIR / Incident Response: Must have hands-on experience investigating escalated security incidents beyond basic SOC alert triage.
• Splunk/SPL: Strong hands-on experience required. Preference for candidates who have written SPL for detections, correlation searches, enrichment, lookups, macros, or similar detection content.
• CrowdStrike: Hands-on experience using CrowdStrike/Falcon for security investigations.
• Python: Target 2-4+ years of scripting/automation experience. Should be able to use Python to solve security problems and work with APIs/data.
• AWS: Must be comfortable working with AWS security telemetry/log sources and/or performing cloud security investigations. HIGHLY PREFERRED:
• Zscaler experience, particularly Zscaler web traffic/logging. The team recently onboarded Zscaler and is currently working through significant signal/noise.
• DLP / Data Loss Prevention detection engineering experience.
• Security automation involving APIs, AWS Lambda, log pipelines, enrichment, or security orchestration.
• Cloud forensics and/or malware investigation experience.
• Experience onboarding new security data sources into SIEM/detection platforms.
• Large SaaS, software engineering, fintech, or other cloud-heavy enterprise environment.
SCREENING QUESTIONS:
1. Describe a security detection you personally built or significantly modified. What data sources and detection logic did you use?
2. Describe a complex DFIR/incident investigation where the initial alert did not provide enough information. What additional logs/artifacts did you investigate?
3. How have you used Splunk/SPL beyond reviewing existing alerts? Please provide specific examples of detections, correlation searches, enrichment, lookups, macros, etc.
4. What security-related automation have you built using Python? What problem did it solve and what systems/APIs were involved?
5. What hands-on experience do you have with AWS security telemetry or cloud investigations? Which AWS log sources/services have you worked with?
6. If applicable, describe your hands-on experience with Zscaler and/or DLP. Clarify whether you built/tuned detections, investigated alerts/logs, or primarily administered the platform.
We are seeking a Senior Security Engineer with strong experience across Digital Forensics and Incident Response (DFIR), detection engineering, security automation and cloud security.
This is a hands-on engineering role supporting a large-scale security operations environment. The position will work closely with incident response and data loss prevention teams to investigate complex security activity, improve security visibility, engineer detections and build capabilities that make the broader security operations team more effective.
This is a 12-month remote contract opportunity. Candidates located in Central Time are strongly preferred, with Eastern Time candidates also considered.
Responsibilities
• Perform advanced incident investigations involving endpoint, cloud, malware, identity, application and security telemetry
• Serve as a technical escalation resource for complex security incidents and forensic investigations
• Develop, tune and improve security detections using Splunk and other security platforms
• Write and optimize SPL queries for detection, investigation and security analytics
• Use CrowdStrike and related endpoint telemetry to investigate suspicious activity
• Analyze AWS security and logging data across cloud environments
• Build Python scripts and API-based automation to improve investigation, enrichment and detection workflows
• Identify and onboard additional security data sources to improve visibility and response capabilities
• Partner with DLP teams to develop and improve detections involving web activity, data movement and potential data loss
• Reduce noise and improve signal quality across high-volume security platforms
• Support secure movement and processing of security telemetry through cloud and API-based pipelines
• Evaluate and safely use AI-assisted security capabilities where appropriate
Required Qualifications
• 4+ years of experience in cybersecurity, including hands-on detection engineering and/or DFIR
• Strong experience with Splunk and SPL
• Hands-on CrowdStrike experience
• Experience performing security incident investigations and analyzing security telemetry
• Python scripting or security automation experience
• Experience working with AWS security logs, services or cloud investigations
• Strong understanding of detection engineering concepts and security monitoring
• Ability to independently investigate complex technical problems and develop practical solutions
Must Qualifications
• Experience with Zscaler, particularly web traffic, logging or security monitoring
• Data Loss Prevention (DLP) experience
• Cloud forensics experience
• Malware analysis or endpoint forensics experience
• Experience building security pipelines using APIs, AWS Lambda or similar technologies
• Experience with ServiceNow Security Incident Response
• Experience in a large SaaS, software, fintech or cloud-heavy enterprise environment
• Familiarity with AI-assisted security analysis or AI-related security investigations
The ideal candidate is not simply someone who has deployed security tools. We are looking for someone who has used those tools to investigate difficult security problems, build better detections and improve the capabilities of a security operations team