About the Role
The Senior Detection Engineer is a technical subject matter expert responsible for the technical execution and delivery of Detection Engineering capabilities, working closely with EIP's Threat Management and Response teams, and other Information Security and IT teams. This role leverages automation and AI/ML capabilities with a cutting-edge detection-as-code CI/CD pipeline to deliver and curate custom threat detection content in Splunk.
Responsibilities
- Technical execution and delivery of Detection Engineering capabilities.
- Deliver and curate custom threat detection content in Splunk.
- Partner closely with EIP groups such as Cyber Security Operations Centre (CSOC), Threat Hunting, Cyber Threat Intelligence, and IT teams such as Enterprise Observability to deliver threat detection services.
- Lead and participate in defensive security projects and initiatives.
- Develop custom tools and leverage automation and orchestration for threat detections, malware research and threat intelligence needs.
- Creation and maintenance of policy, standards, procedures, and documentation.
- Use KPIs and other metrics to identify opportunities for process improvements.
Requirements
- Minimum of 4 years' experience with threat hunting, threat research, threat intelligence or incident response.
- Expert level understanding of the threat landscape in adversary tools such as command-and-control (C2) frameworks, remote management and access tools (RMMs), credential theft utilities, proxy and tunneling tools, cloud attack tooling, data exfiltration utilities, malware loaders, ransomware, and post-exploitation frameworks, as well as the tactics, techniques, and procedures (TTPs) associated with their use.
- Experience with SIEM technologies such as Splunk (preferred), Microsoft Sentinel, Google Chronicle, Elastic Stack, Rapid7, CrowdStrike NG-SIEM, Exabeam, Cortex, LogRhythm, IBM QRadar.
- Deep understanding of how complex, multi-stage malware functions.
- Advanced knowledge of security endpoint detection and response, network forensics and malware analysis across systems whether on premise or in varied cloud environments consisting of physical or virtual workloads.
- Extensive experience creating and maintaining custom threat detection rules, leveraging enrichment data from threat intel and attack surface services.
- Self-provided internet service must meet the following criteria: At minimum, a download speed of 25 Mbps and an upload speed of 10 Mbps is required; wireless, wired cable or DSL connection is suggested.
- Work from a dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information.
Skills
- Strong familiarity of MITRE ATT&CK or similar frameworks.
- Experience working under and providing support for regulatory frameworks such as HIPAA, PCI, SOC2, etc.
Location
- Atlanta GA
- Boston MA
- Charlotte NC
- Chicago IL
- Dallas TX
- Ft. Lauderdale or Tampa FL
- Louisville KY
- Baltimore DC Metro
- Nashville TN
- New York Metro NY
Work Type
- Remote
- Hybrid Home/Office
Experience Level
- Senior
Education Level
- Bachelor's degree in Cybersecurity, Information Technology or a related field is preferred.
- Professional certification in a relevant cybersecurity field (i.e., OSCP, GCTI, GREM, etc)
Salary/Compensations
- $106,900 - $147,000 per year
Benefits
- Medical, dental and vision benefits
- 401(k) retirement savings plan
- Time off (including paid time off, company and personal holidays, paid parental and caregiver leave)
- Short-term and long-term disability
- Life insurance
About the Company
- Humana Inc. (NYSE: HUM) is a leading U.S. healthcare company. Through our Humana insurance services and our CenterWell healthcare services, we make it easier for the millions of people we serve to achieve their best health – delivering the care and service they need, when they need it. These efforts are leading to a better quality of life for people with Medicare and Medicaid, families, individuals, military service personnel, and communities at large.
Equal Opportunity
- It is the policy of Humana not to discriminate against any employee or applicant for employment because of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or protected veteran status.
- It is also the policy of Humana to take affirmative action, in compliance with Section 503 of the Rehabilitation Act and VEVRAA, to employ and to advance in employment individuals with disability or protected veteran status, and to base all employment decisions only on valid job requirements.
- This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment.
