Jobs and Careers
AN
Security Analytics Content Engineer (US Remote)
AnomaliUnited StatesRemotefull_timeVerifiedPosted 4 Sept 2024
About the role
Company Description:Anomali is headquartered in Silicon Valley and is the Leading AI-Powered Security Operations Platform that is modernizing security operations. At the center of it is an omnipresent, intelligent, and multilingual Anomali Copilot that automates important tasks and empowers your team to deliver the requisite risk insights to management and the board in seconds. The Anomali Copilot navigates a proprietary cloud-native security data lake that consolidates legacy attempts at visibility and provides first-in-market speed, scale, and performance while reducing the cost of security analytics. Anomali combines ETL, SIEM, XDR, SOAR, and the largest repository of global intelligence in one efficient platform. Protect and drive your business with better productivity and talent retention. Do more with less. Be Different. Be the Anomali. Learn more at http://www.anomali.com.
Job Description:As a Security Analytics Content Engineer, you will lead the design and production of content detection logic and rules used in Anomali's various technologies. This role is responsible for supporting Anomali’s content detection efforts to become a leader in Security Analytics Market. You will also be responsible for building, deploying and testing all SIEM detection rules and logic . Key Responsibilities 1. Threat Analysis and Detection: Analyzing various forms of digital content, such as emails, web pages, and files, to detect potential security threats like malware, phishing attacks, or harmful scripts. 2. Deep Dive into TTPs:Techniques Identification: Identify specific techniques used in the campaign, such as spear phishing, exploitation of public-facing applications, or credential dumping.Tactics Correlation: Correlate these techniques with the tactics in the MITRE ATT&CK matrix, which are broad categories describing the objectives of the adversary, such as "Initial Access", "Execution", "Persistence", etc.Procedures Detailing: Detail the specific procedures or methods used for each technique. For instance, if the technique is 'spear phishing', the procedure might involve sending emails with malicious attachments tailored to specific individualsBehavior Mapping: Map the adversary's behavior to known profiles in the MITRE ATT&CK framework. 3. Development of Detection Rules: Designing and developing detection rules and algorithms to automatically detect harmful content. This involves understanding the latest in machine learning, pattern recognition, and data analysis techniques. 4. Research and Keeping Up-to-date: Staying informed about the latest malware trends, attack vectors, and detection technologies. This involves continuous learning and sometimes participating in cybersecurity research with Anomali's Advanced Threat Research Group. 5. Testing Custom Detection Tools:Develop Custom Scripts/Tools: If applicable, test custom-developed scripts or tools designed for malware detection.Machine Learning Models: Evaluate the effectiveness of any machine learning models that have been trained to detect malware.
QualificationsA Content Detection Engineer typically specializes in identifying and mitigating security threats . This role involves analyzing threat actors , their campaigns, and creating detection rules and algorithms to detect and prevent such attacks. Additionally, the role may create content based on approved customer requests. The role is a blend of cybersecurity knowledge and content analysis skills.
Required Skills/Experience:o Bachelor’s or Master’s degree (preferred) in Cybersecurity, Computer Science, Information Technology, or a related field. Additional experience and CISSP or relevant certifications will be considered in lieu of degree.o Proficiency in programming languages such as Python, Java, or C++.o Proficiency in writing detection rules for Malware and malicious campaigns. o Ability to analyze and interpret logs and alerts from various security tools.o Experience with machine learning and artificial intelligence, especially in content recognition and classification.o Familiarity with data analysis and data mining techniques.o Experience with tools and techniques for detecting malware, phishing attempts, and other malicious content.o Knowledge of network security and protocols, including experience with firewalls, intrusion detection systems, and encryption techn
Job Description:As a Security Analytics Content Engineer, you will lead the design and production of content detection logic and rules used in Anomali's various technologies. This role is responsible for supporting Anomali’s content detection efforts to become a leader in Security Analytics Market. You will also be responsible for building, deploying and testing all SIEM detection rules and logic . Key Responsibilities 1. Threat Analysis and Detection: Analyzing various forms of digital content, such as emails, web pages, and files, to detect potential security threats like malware, phishing attacks, or harmful scripts. 2. Deep Dive into TTPs:Techniques Identification: Identify specific techniques used in the campaign, such as spear phishing, exploitation of public-facing applications, or credential dumping.Tactics Correlation: Correlate these techniques with the tactics in the MITRE ATT&CK matrix, which are broad categories describing the objectives of the adversary, such as "Initial Access", "Execution", "Persistence", etc.Procedures Detailing: Detail the specific procedures or methods used for each technique. For instance, if the technique is 'spear phishing', the procedure might involve sending emails with malicious attachments tailored to specific individualsBehavior Mapping: Map the adversary's behavior to known profiles in the MITRE ATT&CK framework. 3. Development of Detection Rules: Designing and developing detection rules and algorithms to automatically detect harmful content. This involves understanding the latest in machine learning, pattern recognition, and data analysis techniques. 4. Research and Keeping Up-to-date: Staying informed about the latest malware trends, attack vectors, and detection technologies. This involves continuous learning and sometimes participating in cybersecurity research with Anomali's Advanced Threat Research Group. 5. Testing Custom Detection Tools:Develop Custom Scripts/Tools: If applicable, test custom-developed scripts or tools designed for malware detection.Machine Learning Models: Evaluate the effectiveness of any machine learning models that have been trained to detect malware.
QualificationsA Content Detection Engineer typically specializes in identifying and mitigating security threats . This role involves analyzing threat actors , their campaigns, and creating detection rules and algorithms to detect and prevent such attacks. Additionally, the role may create content based on approved customer requests. The role is a blend of cybersecurity knowledge and content analysis skills.
Required Skills/Experience:o Bachelor’s or Master’s degree (preferred) in Cybersecurity, Computer Science, Information Technology, or a related field. Additional experience and CISSP or relevant certifications will be considered in lieu of degree.o Proficiency in programming languages such as Python, Java, or C++.o Proficiency in writing detection rules for Malware and malicious campaigns. o Ability to analyze and interpret logs and alerts from various security tools.o Experience with machine learning and artificial intelligence, especially in content recognition and classification.o Familiarity with data analysis and data mining techniques.o Experience with tools and techniques for detecting malware, phishing attempts, and other malicious content.o Knowledge of network security and protocols, including experience with firewalls, intrusion detection systems, and encryption techn
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s