Back
Bulgaria   Bulgaria   Engineer   Sap -

Senior Detection and Response Engineer

This listing was posted on SAP.

Senior Detection and Response Engineer

Location:
Sofia
Description:

We help the world run better Our company culture is focused on helping our employees enable innovation by building breakthroughs together. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and future-focused work. We offer a highly collaborative, caring team environment with a strong focus on learning and development, recognition for your individual contributions, and a variety of benefit options for you to choose from. Apply now! We are looking for an engineer Hands-on experience in implementing a (security) orchestration and (hyper) automation platform. The ideal candidate would have SOC L2/L3 background and the ability to significantly contribute to the design and implementation of playbooks The candidate should have a good understanding of entities and data models associated with various log types, a bonus for cloud workloads specific logs. What you'll do Deploy a new SOAR/hyper-automation tool Collaborate with the SOC and lead playbook creation Understand problems with detection use-cases and identify opportunities to group alerts based on entities or other criteria. Use your coding, data analytics and investigation skills to write new integrations between SOAR, detection and security tooling, ticketing systems, CMDB, TI enrichment platforms Contribute to decision-making into what information needs to be enriched and when, what is relevant and less-relevant for a L1 triage analyst Participate in the integration with GPT models and prompting and training ML models for alert triage. Detection Rule testing and tuning to identify and reduce False-Positive & False-Negative Depending on priority, assist in writing/customizing detections after red/purple teaming engaments. What you'll bring Ideally SOC experience in a datacenter environment (MSP) A good understanding of network security (cloud is a bonus) Python skills. (data modelling, ML is a bonus) Experience writing API connectors and tool plugins. Technical proficiency on Linux Experience building dashboards and processes around use-case testing , versioning Security tool integration experience, familiarity with common information and log formats 5+ years of experience in Security including but not limited to: Threat Intel, Threat Detection, Cloud Security and or SOC experience, Automation Research mindset, with a hold on where to look for relevant information pertaining to cloud threats, vulnerabilities and key adversary’s modes of interest. An understanding of CI/CD, versioning tools, Jira/Kanban Nice to have Advanced Splunk/Phantom experience (or other SIEM/SOAR equivalent) Infrastructure as code experience Knowledge of public cloud resources and control plane threats and vulnerabilities, and how it applies to MITRE ATTACK Framework. Platform knowledge around AWS, GCP and Azure, specifically around security configuration and monitoring. Experience with Threat Intel ingestion and generation Splunk ES certification, GIAC GMON, GCDA, GCTI, GCFE or other relevant certifications or projects experience Experience with BAS tools, commercial or open source. #SAPECSCareers We build breakthroughs together SAP innovations help more than 400,000 customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with 200 million users and more than 100,000 employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, we build breakthroughs, together. We win with inclusion SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better and more equitable world. SAP is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to the values of Equal Employment Opportunity and provide accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: XXXX@sap.com For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy . Specific conditions may apply for roles in Vocational Training. EOE AA M/F/Vet/Disability: Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability. Successful candidates might be required to undergo a background verification with an external vendor. Requisition ID: 391475 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid.
Company:
Sap
June 1 on SAP
Visit Our Partner Website
This listing was posted on another website. Click here to open: Go to SAP
Important Safety Tips
  • Always meet the employer in person.
  • Avoid sharing sensitive personal and financial information.
  • Avoid employment offers that require a deposit or investment.

To learn more, visit the Safety Center or click here to report this listing.