Post Job Free
Sign in

Security Engineer - Surface Coverage, Detection Engineering

Company:
Meta
Location:
Washington, DC
Posted:
May 07, 2024
Apply

Description:

Meta Security is looking for a Security Engineer with experience in threat modeling, TTP identification, and detection engineering.

You’ll work alongside Software Engineers and Offensive Security Engineers to identify critical assets, assess the top risks, and evaluate potential attacks against Meta systems.

You will be working across engineering teams supporting Production and Corporate systems to develop detection and response automation leveraging both industry-standard and custom detection and response platforms.

You’ll generate detection ideas utilizing some of the world’s largest data sets and build on top of hyper-scale data pipelines.

Responsibilities:

Security Engineer - Surface Coverage, Detection Engineering Responsibilities:

Lead cross-functional projects to improve our capabilities to effectively detect and respond to security incidents

Review security architecture of large-scale custom and commercial systems and independently propose logging, detection and prevention controls

Perform TTP-based Threat Modeling for a wide variety of assets including endpoints, mobile, servers, internal services, public & private cloud environments and networking equipment

Perform analysis against logs from a variety of sources (e.g., individual host logs, network traffic logs) to identify potential threats and detection ideas

Build response workflows and actions that auto-resolve false positives and provide context scaling our ability to investigate

Support security incident response in a cross-functional environment and drive incident resolution

Design and implement attack testing automation to validate detection coverage

Build logging pipelines using our custom datasets and infrastructure

Qualification and experience:

Minimum Qualifications:

5+ years of experience in Detection & Response Engineering or similar Security Engineering role

Experience building complex automations and integrations using SOAR platforms

Bachelor's degree or equivalent experience in Security

Experience designing systems used for responding to both external and insider threats

Experience analyzing network and host-based security events

Knowledge of networking technologies, specifically TCP/IP and the related protocols

Knowledge of operating systems, file systems, and memory structures on Windows, MacOS and Linux

Coding/scripting experience in one or more general purpose languages

Experience with attacker tactics, techniques, and procedures

Preferred:

Preferred Qualifications:

Background in security-focused software engineering, designing large scale systems and data pipelines, or offensive security

Experience in threat hunting including leveraging intelligence data to proactively identify and iteratively investigates suspicious behavior across networks and systems

Broad knowledge across the Security domain, as well as deep focus in one (or more) areas such as Logs and events processing, Incident Management, Digital Forensics, Offensive Security Testing, Detection and/or Response tooling development

Apply