- Design, develop, and maintain YARA rules for threat detection and malware analysis, ensuring high accuracy and effectiveness.
- Conduct research and analysis to identify emerging threats and vulnerabilities and develop proactive detection mechanisms.
- Identify and implement detection use cases based on emerging threats and TTPs using MITRE ATTCK framework.
- Contribute to optimization of detection rules to eliminate false positives and improve detection efficiency.
- Collaborate with cross-functional teams to understand customer requirements and customize cybersecurity solutions to meet their needs.
- Participate in security incident response activities, providing technical expertise and support as needed.
- Stay abreast of the latest cybersecurity trends, technologies, and best practices, and share knowledge with the team.
- Work closely with customers to understand their security challenges and requirements and provide expert guidance and support.
Qualifications
- Bachelor s degree in computer science, Information Security, or related field.
- 3 years of experience in cybersecurity,
with a focus on detection engineering and implementation.
- Proficiency in creating and maintaining YARA rules for threat detection and malware analysis.
- Solid understanding of MITRE ATTCK framework and developing detection rules based on it.
- Solid understanding of data ingestion techniques and technologies, including log management systems and data lakes.
- Knowledge and experience in developing use cases for Cloud, Identity, Endpoint and Data Exfiltration use cases.
- Hands-on experience with SIEM (Security Information and Event Management) solutions such as Splunk, ELK, or QRadar.
- Excellent analytical and problem-solving skills, with the ability to troubleshoot complex technical issues.
- Robust communication and interpersonal skills, with the ability to effectively collaborate with internal teams and customers.
- Relevant cybersecurity certifications (e.g., CISSP, CEH, GIAC) are a plus.