Detection Engineer
Remote
- Full time
About the job
This vacancy has now expired. Please see similar roles below...
"We are looking for a Detection Engineer with KQL or Yara-L experience. If you have detection engineering experience with other SIEM solutions and are up for a new challenge, we would like to hear from you. The successful candidate will be responsible for developing, implementing, and continuously improving Admiral’s threat led security detection analytics and response capabilities. You will need to understand the changing threat landscape, identify opportunities for improvements in existing detections, develop new detections, and ensure appropriate detection coverage for the organisation. You will work closely with multiple teams, including Security Operations, Incident Response, and Threat Intelligence, in a fast moving and agile environment.
You will be responsible for developing and driving siem and endpoint threat detections both day-to-day and strategically. You are expected to seek out effective and comprehensive detection logic thus, ensuring detections are high fidelity and thoroughly tested, and that detection rules are available and understood by operational cyber security teams.
Develop security specific content necessary to implement Use Cases that transform into correlation queries, templates, reports, rules, alerts, and dashboards.
Responsibilities
- Creation of new detections from use cases from business related projects threat modelling and threat intelligence.
- Create custom analytic rules to detect threats.
- Continuous development and testing of detection rules and tooling.
- Drive the improvement of our Detection Framework, its methodologies, and lifecycles.
- Guidance and Support for Analysts in release, implementation, and tuning phases
- Contribute to the review and lessons learned of Blue, Red and Purple Team engagements.
- Conduct knowledge-sharing sessions for edge cases from emerging threats.
- Contribution to the improvement of environmental detections (data source gap analysis)
Desirable Skills, Experience and Behaviours
- KQL Analytics or Yara- L experience is a Must.
- Configuration of Data connectors for Security Events, Threat Intelligence Platforms, Linux Syslog, Office 365, etc
- 2 years+ experience in Cyber Security as a Detection Engineer
- Knowledge of attacker tools and evasion techniques
- Working knowledge of at least one major programming language, including scripting languages like Python and PowerShell
- Good understanding of Windows and Linux Operating Systems
- Translate threat intelligence into actionable detection logic.
- Knowledge of cloud infrastructure, cloud security and cloud APIs is advantageous.
- Knowledge of Active Directory threats
- Experience working with Mitre Attack Framework
- Strong team working skills with ability to build trusted relationships with people and groups with diverse backgrounds, and to influence at all levels.
- Professional, with attention to detail - always seeking quality and excellence in their work.
- Collaborative and engaging approach to problem solving and a willingness to work as part of the team.
- Passionate for diversity, recognising the innovation and competitive edge that comes from a diverse highly skilled team where equal opportunities are truly valued.
- A problem-solver, always seeking the best solution for the right outcome.
- Friendly manner, with a willingness to adapt style and approach to achieve quality results.
- Self-motivated, results-focussed, pragmatic with the ability to manage conflicting deadlines and prioritise.
- SC-200 Certification advantageous
Our Commitment to You
At Admiral, we are committed to being a diverse and inclusive workplace. Admiral is proud to be an equal opportunities employer and does not discriminate on the basis of race, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), national origin, gender, gender identity, sexual orientation, disability, age, or any other legally protected status.
All qualified applicants will receive equal consideration for employment.
Benefits and Work-Life Balance
At Admiral, we are proud to be a diverse business where we put our people and customers first. We have great benefits to ensure employees have a great work-life balance; it's one of the reasons we’re consistently voted one of the Sunday Times Best Big Companies to Work For in the UK.
All colleagues will receive 33 days holiday (including banks holidays) when they join us, and this will increase with length of service, up to a maximum of 38 days (including banks holidays). You also have the option to buy or sell up to five days of annual leave in addition to your allocation.
You can also view some of our other key benefits here.
- Full time
- Information Security
__jobinformationwidget.freetext.LocationText__
Remote
Talent Specialist - Tech & Data
What areas do you look after?
I work within the Business Support team and I recruit within the Tech and Cyber space.
Tell us about you and your Admiral story?
I joined Admiral in February 2022 after working in external recruitment. I started recruiting for Pioneer and then soon moved over to Admiral Money. After 1 year I made a big change and now my focus sits within the Tech and Cyber space. I have learnt so much already and can’t wait to see where I am in a years’ time.
Why would you recommend Admiral?
I knew I wanted to work for Admiral very early on in my career, just purely off their glowing reviews and reputation. Little did I know that’s just the surface! The culture is second to none, I have never worked somewhere that cares and respects their employees as much as Admiral do. I constantly recommend Admiral to my friends and family, and some have even taken the step and joined!
Related jobs
Salary
Location
Remote
Job Type
Full time
Location
Remote
Brand
Admiral Group
Department
Claims, Household
Office address
Remote
Description
Admiral Household Claims is an exciting department that is experiencing growth as we seek to increase the size of the business. The position of Loss Adjusting Services Team Manager- ‘South’, exists
Reference
10234
Expiry Date
01 Jan 0001
Vacancy managed by
Sophie Smith-PhillipsVacancy managed by
Sophie Smith-PhillipsSalary
Location
Cardiff
Job Type
Full time
Location
Cardiff
Brand
Admiral Money
Department
Finance Services
Office address
Tŷ Admiral, David Street, Cardiff, CF10 2EH
Description
Admiral Money is hiring for a DevOps Engineer to join the team! Admiral Money is an exciting division of Admiral Group. We have the freedom and innovation of a small start up with the security of
Reference
10636
Expiry Date
01 Jan 0001
Vacancy managed by
Eden DaviesVacancy managed by
Eden DaviesSalary
Location
Cardiff
Job Type
Full time
Location
Cardiff
Brand
Pioneer
Department
Veygo
Office address
Tŷ Admiral, David Street, Cardiff, CF10 2EH
Description
We’re looking for a Senior Full Stack Engineer to join our team at Veygo! About Veygo At Veygo our world is learner and temporary pay-as-you-go car insurance. We know people's lifestyles a
Reference
10421
Expiry Date
01 Jan 0001
Vacancy managed by
Eden DaviesVacancy managed by
Eden DaviesOur Benefits
Admiral employees work hard to keep us at the top of our industry, and are rewarded for it—with competitive pay, a share package, career growth and development opportunities and some other great benefits, too!
People who like what they do, do it better.
Be You
Financial & Mortgage
Advice
24-Hour
Ecare
Cycle to Work
Scheme
Annual Holiday
Allowance
Flexible
Working
Simply
Health
Private Health
Cover
Critical Illness
Cover
Grow & Progress
Learning and
Development
Educational
Sponsorship
Accredited
Qualifications ILM
iLearn
Online Learning
Buy a Book
Scheme
Developmental
Coaching
Port of
Calls
Internal
Mobility
Make a Difference
Groups and
Societies
Socials and Team
Days Out
Multi Faith / Quiet
Rooms
Admiral Community
Fund
Give as You
Earn
Awards and Star
Lunches
Corporate Social
Responsibility
Impact
Hours
Share In Our Future
Share
Schemes
Refer a Friend
Bonus
Colleague and Family
Insurance Discount
Group Life
Assurance
Pension
Scheme
Life Event
Loan
Tickets to Sponsored
Events
Tusker Salary
Sacrifice