Cyber Security Engineer - Threat Detection at a Major Japanese Bank
Indexed description
Role Objectives
- Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness.
- Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services.
- Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond.
Map detections and coverage to relevant frameworks, including MITRE ATT&CK, to support measurable improvements in monitoring and response capabilities.
Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content.
Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency.
Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements.
Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks.
- Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience.
- Minimum of 3 years of relevant cybersecurity, detection engineering, SOC engineering, security analytics, or security operations experience.
Experience with cloud SIEM, UEBA, EDR, SOAR, data lake, or related detection and monitoring technologies.
- Strong knowledge of query languages and data analysis techniques used to investigate security events and develop detection logic.
- Experience developing detection-as-code pipelines, automation, scripts, or repeatable processes to improve security operations efficiency.
Experience mapping detections to MITRE ATT&CK or similar security frameworks.
Working knowledge of Windows and Linux operating systems, common enterprise infrastructure, and cloud environments.
Strong troubleshooting, analytical, and problem-solving skills, with the ability to identify root cause and recommend practical improvements.
Ability to balance operational responsibilities with project delivery in a fast-paced environment. Strong documentation, communication, collaboration, and stakeholder management skills.
Demonstrated ownership, attention to detail, and ability to work effectively in a global team environment.
- Additional cybersecurity experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is a plus.
Mid (5-7 Years)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search