Jobs and Careers
FA

Senior Security Engineer - Detection and Response

Fanatics
United States, United Statesfull_timeVerifiedPosted 22 Mar 2024
💰 $180,000/yr($128,000/yr$180,000/yr)

About the role

Fanatics is looking for a Senior Security Engineer to join our Detection and Response team. The ideal candidate is well versed in incident response, passionate about engineering solutions to security problems, and enjoys driving process improvement through automation. In this role, you will have incident response duties in addition to being responsible for the design and development of the detections and automated workflows that we need to scale our incident response capabilities. 

Information Security team members are given a great deal of autonomy in the pursuit of keeping Fanatics secure and a successful candidate will demonstrate a strong work ethic, superior communication skills, and are expected to be comfortable and effective working independently and as part of a larger, highly-distributed team. We're looking specifically for people who place an emphasis on usable security. Fanatics is a fast-growing company and our security program needs to be able to keep pace with that growth while not disrupting innovation.


Responsibilities:

  • Develop, test, and maintain SOAR workflows, integrations, and scripts to improve the speed and consistency of incident response through automation.
  • Author and maintain documentation for all detections, automated response workflows, integrations, and scripts.
  • Respond to security incidents, perform investigations, conduct incident analysis, and articulate potential risks and remediation strategies to stakeholders.
  • Participate in a weekly 24/7 on-call rotation, providing opportunities to see your detections and automated workflows at work on the front line.     
  • Use detection engineering best practices to develop and continuously optimize alerts, allowing us to spend our cycles effectively and spot anomalies quickly.
  • Contribute to improving processes, procedures, and technologies used for detection and response, enabling us to improve after each incident.
  • Conduct proactive threat hunts and threat modeling exercises to identify and pinpoint potential security threats, drawing on insights into attacker TTPs to identify potential IOCs and incorporate findings into security controls.
  • Author and maintain incident response plans and response playbooks, including identification, remediation, containment, and eradication procedures. 
  • Work closely with other engineering teams to continuously provide requirements and use cases for enabling technologies including but not limited to SIEM, SOAR, EDR, Intrusion Detection Systems, HIPS, Web Proxy/Content Filtering, System Hardening, Identity Management, and PKI.

 Experience and Skills:

  • Strong SOAR development skills and proven experience automating security response workflows in an enterprise environment.
  • Experience using scripting, REST APIs, and query languages for automation, alert enrichment, and detections.
  • Defensive practitioner who understands offensive security and the actual scenarios that lead to compromise.
  • Hands-on incident response experience, including managing complex investigations with many stakeholders.
  • Working knowledge of adversary TTPs and experience using MITRE ATT&CK principles to detect and respond to security incidents.
  • Experience with enterprise SIEM platforms including the design and development of detections, reports, and dashboards.
  • Ability to analyze endpoint, network, and application logs for anomalous events, including hands-on experience with data analysis, modeling, and correlation at scale.
  • Experience using penetration testing and ATT&CK framework tools to simulate adversarial behaviors and translate those behaviors into detections.
  • Strong OS administration skills including conceptual knowledge of OS internals and understanding of malware functionality and persistence mechanisms.
  • Exceptional communication skills and a proven track record of communicating effectively with internal and external stakeholders at all levels.
  • Robust analytical and problem-solving capabilities, with a keen eye for objectively evaluating security risks.
  • High level of commitment, energy, and creativity with the ability to work in a fast paced, rapidly changing environment.
  • Meticulous attention to detail with strong organizational skills and ability to prioritize work effectively.
  • Proficiency using and managing a variety of security tools and technologies, such as: MFA, IDS/IPS, EDR, WAF, and Vulnerability Management.
  • Experience using CI/CD tools like GitLab or GitHub.
  • Experience working in a hybrid environment that includes on-premise and cloud based systems.

Desired Qualifications:

  • 5+ years of experience working in technical information security roles with a focus on security automati

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Fanatics

View company profile →