Senior Detection Engineer
Company Description
ServiceNow is making the world of work, work better for people. Our cloud‑based platform and solutions deliver digital workflows that create great experiences and unlock productivity for employees and the enterprise. We're growing fast, innovating faster, and making an impact on our customers' and employees' lives in significant and important ways. With over 6,900 customers, we serve approximately 80% of the Fortune 500, and we're on the 2020 list of FORTUNE World's Most Admired Companies.®
We’re looking for people who are ready to jump right in and help us build on our incredible momentum, our diverse, engaged workforce, and our purpose to make the world of work, work better.
Learn more on Life at Now blog and hear from our employees about their experiences working at ServiceNow.
Job Description
ServiceNow is changing the way people work. With a service-orientation toward the activities, tasks and processes that make up day-to-day work life, we help the modern enterprise operate faster and be more scalable than ever before. ServiceNow is looking to expand its Global Threat Operations with Senior Detection Engineer. As a member of the Threat Intelligence team, you will drive security research and detection development into production alerting for the Security Operation team. The Detection Engineer’s primary responsibility is to research, onboard and tune new detection.
What you get to do in this role:
- Identify new detection use cases and support maintaining current use cases.
- Create alert original queries and peer review others queries with stakeholders.
- Implement changes to existing alert queries for performance improvements, threshold adjustments or exclusion filters.
- Monitor performance of telemetry rules and remedy issues.
- Engage in threat hunting tool development and operations activity.
- Support various IT and Security Engineering projects with understanding on how to apply feasible security monitoring techniques.
- Collaborate engineering, management, and incident response teams on researching and developing new detections.
Qualifications
In order to be successful in this role, we need someone who has:
- Minimum 8 years experience in information security. Preferably in the domains of Security Operations or Security Engineering.
- Minimum 3 years experience of using Splunk Search Processing Language (SPL).
- Working knowledge and experience with major public cloud platforms.
- Fluent in MITRE ATT&CK framework and its practical applications.
- A technical mindset with great attention to detail.
- Deep understanding of Windows and *nix operating systems, endpoint applications, networking protocols and device.
- Project management skills, being able to track multiple projects simultaneously.
- Expertise in a wide variety of logs sourced from network appliances, operating systems and applications.
- Concise verbal and written communication skills.
- Proficient regex pattern matching skills
- Experience with automating security (SOAR, AWS Lambdas, etc..)
- Scripting experience with any modern language.
- Understanding of OWASP, CVSS, and application security concepts
- General knowledge of software development operations at a SaaS company.
- Experience with the ServiceNow platform is a bonus
Additional Information
ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law.
If you require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at [email protected] for assistance.
For positions requiring access to technical data subject to export control regulations, including Export Administration Regulations (EAR), ServiceNow may have to obtain export licensing approval from the U.S. Government for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by the U.S. Government.
Please Note: Fraudulent job postings/job scams are increasingly common. Click here to learn what to watch out for and how to protect yourself. All genuine ServiceNow job postings can be found through the ServiceNow Careers site.