Staff Detection Engineer at ServiceNow

| Remote
Sorry, this job was removed at 5:01 p.m. (PST) on Monday, July 20, 2020
Find out who's hiring in Seattle.
See all Developer + Engineer jobs in Seattle
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.

Description

ServiceNow is changing the way people work. With a service-orientation toward the activities, tasks and processes that make up day-to-day work life, we help the modern enterprise operate faster and be more scalable than ever before.

 

ServiceNow is looking to expand its Telemetry capabilities with an additional Detection Engineer. As a member of the Telemetry Engineering team you will drive security alerting into production for Security Operations. The primary role of the content engineer is to have total oversight of all things telemetry. This ownership includes creation of new alerts/dashboards, troubleshooting complex alert query fixes, managing development workflow, tracking change control, and adherence to regulatory obligations. This role will special will specialize in user behavior analytics (UBA) with a direction to build anomaly detection and complex threat modeling. 

 

Duties and Responsibilities:

  • Configure UBA anomaly and threat modeling detections.
  • Assist with the entire Telemetry creation and change management from beginning to end.
  • Collaborate with fellow cyber threat intelligence analysts and threat hunters teammates on new use cases.
  • Troubleshoot advanced query logic and work with various teams to derive the best solution.
  • Create initial alert queries and validate output with stakeholders.
  • Implement changes to existing alert queries for performance improvements, threshold adjustments or exclusion filters.
  • Triage and prioritize telemetry requests based off risk, impact and complexity.
  • Deploy telemetry changes into production using a formalized process, to include ServiceNow Security Operations module integration for security incident creation.
  • Provide telemetry item’s purpose to the documentation support analyst.
  • Maintain telemetry inventory for regulatory and compliance audits.
  • Coordinate with incident response team with telemetry needs for security investigations.
  • Create meaningful dashboards for detection patterns or behavior monitoring. This will sometimes require statistical analysis or advanced visualizations.
  • Track progress and escalate problem areas when needed.

 

In order to be successful in this role, we need someone who has:

  • 3-5 years’ experience in information security. Preferably in the domains of Security Operations or Security Engineering.
  • 2 years minimum of using Splunk Search Processing Language (SPL). 
  • Experience writing UBA detection rule writing.
  • Prior experience with SIEM technology and log aggregation applications.
  • Project management skills in order to track multiple updates with an organized method.
  • Ability to understand various log types from a variety of sources such as network devices, operating systems and application specific logs.
  • Proficient regex pattern matching skills.
  • Knowledge of MITRE ATT&CK Matrix is a bonus.
  • Familiar with effective visualizations and dashboarding fundamentals.
  • Concise verbal and written communication skills.
  • Experience with the ServiceNow platform is a bonus.
  • Experience with the Securonix is a bonus.

 

Candidates must be able to meet all federal government security screening requirements as indicated: Federal security screening requirements call for applicant to verify U.S. Citizenship. Additional customer screening requirements may include additional items such as, but not limited to: specialized agency background checks (either national or local) and fingerprinting, as well as the ability to obtain a government personnel security clearance.

We provide competitive compensation, generous benefits and a professional atmosphere. This is a very collaborative and inclusive work environment where individuals strong on aptitude and attitude will have an opportunity to grow their professional careers through working with some of the most advanced technology and talented developers in the business.

 

 

 

ServiceNow is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, age, disability, gender identity, or veteran status. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at (408) 501-8550, or talent.acqu[email protected] for assistance.

Read Full Job Description
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.

Technology we use

  • Engineering
    • JavaLanguages
    • JavascriptLanguages
    • PythonLanguages
    • SqlLanguages
    • jQueryLibraries
    • jQuery UILibraries
    • ReactLibraries
    • AngularJSFrameworks
    • HadoopFrameworks
    • Node.jsFrameworks
    • Ruby on RailsFrameworks
    • HBaseDatabases
    • Maria DBDatabases
    • MySQLDatabases
    • OracleDatabases

Location

We’re on the edge of Lake Washington at Carillon Point in Kirkland. Right now, we're physically distanced but trying to stay socially connected!

An Insider's view of ServiceNow

What’s the vibe like in the office?

You make decisions every day that help people. My work makes a big difference, and that’s satisfying.

Medha

Senior application developer

What projects are you most excited about?

I wanted to work at a growing company. We're focused, customer-centric, and you can't beat the platform.

Olum

Project manager

What are some things you learned at the company?

Our purpose is empowering. The company's putting a lot into the culture, the employees - they're investing in us.

Marina

Creative director

What is your vision for the company?

Amazing products that create great employee and customer experiences and make work, work better, is our passion.

CJ

Chief product officer

What is your vision for the company?

Taking a long-range view, we've got the spirit of a start-up and the resources to deliver with high quality.

Preetam

Software engineer

What are ServiceNow Perks + Benefits

ServiceNow Benefits Overview

We make work better for people—including our own. From work environments that help us do our best work, to benefits and a culture that encourage employees to stay healthy, happy, engaged, and growing, we keep our people at the center of everything we do.

Culture
Volunteer in local community
Through our #GivingAtNow program, our Kirkland offices schedules volunteer opportunities throughout the year.
Eat lunch together
Diversity
Dedicated Diversity/Inclusion Staff
Diversity manifesto
Someone's primary function is managing the company’s diversity and inclusion initiatives
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability Insurance
Dental Benefits
Vision Benefits
Health Insurance Benefits
Wellness Programs
Onsite Gym
Retirement & Stock Options Benefits
401(K)
401(K) Matching
Company Equity
Employee Stock Purchase Plan
Purchase company stock at a 15% discount semi-annually
Performance Bonus
Match charitable contributions
Child Care & Parental Leave Benefits
Generous Parental Leave
Remote Work Program
Work remotely on occasion as needed.
Adoption Assistance
Vacation & Time Off Benefits
Unlimited Vacation Policy
Generous PTO
ServiceNow offers unlimited paid vacation time starting at Day 1.
Paid Volunteer Time
Our employees receive 20 hours per year of paid volunteer time.
Paid Holidays
Paid Sick Days
Perks & Discounts
Beer on Tap
On-site!
Casual Dress
Commuter Benefits
Pre-tax contribution plan for commuter expenses.
Company Outings
Site social activities periodically
Stocked Kitchen
Some Meals Provided
Lunch provided every Friday!
Happy Hours
Steps away from awesome restaurants and bars.
Parking
Free parking
Pet Friendly
Professional Development Benefits
Job Training & Conferences
LinkedIn Learning access, numerous internal training programs, conference attendance options.
Tuition Reimbursement
Up to $5,250 reimbursed annually for qualified expenses
Diversity Program
Continuing Education stipend
We offer $5000 annualy for continuing education.
Online course subscriptions available
More Jobs at ServiceNow35 open jobs
All Jobs
Finance
Data + Analytics
Dev + Engineer
Operations
Product
Project Mgmt
Sales
Content
Developer
new
Remote
Project Mgmt
new
Remote
Content
new
Remote
Developer
new
Remote
Data + Analytics
new
Kirkland
Product
new
Remote
Project Mgmt
new
Remote
Developer
new
Kirkland
Sales
new
Remote
Developer
new
Kirkland
Developer
new
Kirkland
Developer
new
Kirkland
Developer
new
Kirkland
Developer
new
Kirkland
Developer
new
Kirkland
Sales
new
Kirkland
Developer
new
Kirkland
Data + Analytics
new
Kirkland
Apply now
By clicking continue you agree to Built In’s Privacy Policy and Terms of Use.
Save jobView ServiceNow's full profileSee more ServiceNow jobs