Senior Threat Detection Engineer
Reinsurance Group of AmericaAbout the role
You desire impactful work.
You’re RGA ready
RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 500 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.
A Brief Overview
Responsible for developing and executing standards, procedures, and processes to monitor, maintain, and create new detections. Manages telemetry health monitoring to ensure existing monitoring/alerts are performing as intended. Enable global Security Operations by participating in on-call rotations, alert triage, investigations, and engineering.
What you will do
Participates in 24/7 on-call rotation, alert triage, and investigations
Support and drive the Incident Response Lifecycle (readiness, training, response, command, post-mortem) efforts
Utilizing CI/CD pipeline, coordinates monitoring, maintaining, and optimizing existing detections to ensure high fidelity and low noise detections, inclusive of Detection Playbooks.
Supports and the validation of security telemetry health and the identification of gaps in telemetry that may introduce risk to the organization. Develops processes and standards for validation of security telemetry.
Develops and supports efforts to identify and close detection and telemetry gaps.
Leads and contributes to purple team exercises for Monitoring and Detection by assisting with hunt, data and detection validation.
Supports metric and reporting initiatives to drive strategic business decisions and leadership situational awareness.
Drives investigations to completion and identifies and documents systemic issues, working with in the team to ensure tracking and mitigation.
Supports purple team engagements for the SOC, identifying and tracking findings. ensuring actionable detection recommendations and security improvements.
Perform other duties as assigned.
Qualifications
Bachelor’s Degree in Arts/Sciences (BA/BS) or equivalent experience required
3+ Years of experience in one or more areas; incident response, security engineering, offensive security, threat emulation, penetration testing, or security operations required
Experience identifying and addressing telemetry gaps in security monitoring required
Experience contributing to purple team exercises, including supporting risk hunting, telemetry validation, and detection efficacy required
Experience developing and supporting cybersecurity metrics and reporting to support security operations required
Experience creating automation/workflows to scale security operations required
4+ Years of relevant experience preferred
Ability to handle complex incidents and evolve strategies based on new information required
Data analytical skills with the ability to investigate network, host, cloud and identity platforms required
Ability to work independently within a globally distributed environment required
Strong written and verbal communications skills required
Ability to quickly adapt to new methods, work under tight deadlines and stressful conditions required
Mid level investigative, analytical and problem solving skills required
Ability to set goals and handle multiple tasks, clients, and projects simultaneously required
Ability to appropriately balance priorities, deadlines, and deliverables required
Ability to work well within a team environment and participate in department/team projects required
Technical Requirements: Windows, Mac, and Linux internals, Scripting (Powershell/Python/Javascript/Typescript) required
Cloud computing (AWS), M365 suite and ecosystem, Microsoft domain environments, IAM/AAA technologies and architectures (Active Directory, Okta, OpenID, SAML, Oauth, JWT), Physical and Virtual Networking technologies and architecture, SIEM (Splunk), EDR (CrowdStrike, Microsoft Defender), Email security, DNS required
Technical Requirements: Cloud Computing (GCP, Azure), Forensic tools (FTK, Encase, X-Ways, SIFT), Service Now preferred
Professional industry certification preferred
#LI-CW1
#LI-hybrid
What you can
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s