Senior Cyber Detection Engineer

3 weeks ago


London, United Kingdom JPMorgan Chase & Co. Full time

Senior Cyber Detection Engineer – Cloud Technical Lead You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience who enjoys researching TTPs and the threat landscape and translating that research data into high quality detections. Your role involves actively seeking effective and comprehensive detection strategy and capabilities, ensuring detections are thoroughly tested, alerts are relevant, of value and playbooks are available to and understood by cybersecurity operations teams.
As one of the team’s specialists on cloud technologies, you will work to mature the Attack Analysis team in how we secure, monitor and respond to incidents in both private and public cloud environments. You will work with internal security engineering and cloud engineering teams to ensure that Attack Analysis requirements are represented in the architecture, design and implementation of cloud environments. You'll help design, write and automate detection and incident response processes and tools for public and private cloud environments.
Working in cybersecurity takes passion for technology, speed, a desire to learn, and vigilance in order to keep every asset safe. Working with your internal team, as well as technologists and innovators across our global network, your ability to identify threats, provide intelligent analysis and positive actions will stop crimes and strengthen our data.
As a member of the Attack Analysis team, you will fit into a Global team providing 24/7 monitoring and Incident Response , acting as the frontline for attacks against the firms' infrastructure. As a Detection Engineer, your role will include advanced analysis, threat hunting, evaluation of new security technology as well as ensuring larger technology projects at the company are ready to be integrated into the Attack Analysis team and monitoring function. This could include running training sessions for the team in range or virtual environments, leading hunting exercises, serving as a technical escalation point and coaching the team through adopting monitoring responsibility.
Public/Private Cloud Engineering and Incident Response,Detection Engineering, Threat Modelling.Hands-on experience withat least 1 cloud platform (AWS, Azure, GCP) is required.
6 years of working experience with at least 4 years of hands-on experience in Security Operations and Incident Response or Computer Network Operations (CNO) or Computer Network Defense (CND).
Hands-on experience with at least 1 cloud platform (AWS, Azure, GCP) including infrastructure, security and cloud APIs.
Bachelor’s degree in Computer Science, Information Security, Digital Forensics or equivalent qualification.
Excellent written and verbal communication skills to describe security event details and technical analysis with audiences within the cybersecurity organization and other technology groups.
Ability to research TTPs and develop high fidelity detections in various tools/languages including but not limited to: Splunk, CrowdStrike, Azure Sentinel, Suricata, Snort.
Ability to use data science and analytical skills to identify anomalies over large datasets.
Experience with log analysis and correlation of large datasets from multiple data sources to identify and investigate attack patterns.
Experience with threat hunting on a large, enterprise network both as an individual and leading hunting exercises with other team members.
Ability to perform packet-level analysis and strong understanding of common network protocols and the OSI model.
Experience using scripting languages (Python, Powershell, Bash, etc.) to parse machine-generated data, interact with REST APIs and automate repetitive tasks.
Experience with Digital Forensics & Incident Response processes including memory & file system analysis methodologies.
Experience with analyzing Endpoint Detection & Response (EDR) telemetry and excellent knowledge of operating system internals (Windows, Linux, macOS).
Knowledge with command line tools across Windows and Linux.
Familiarity with malware analysis (both static and dynamic), binary triage, and file format analysis.
You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience who enjoys researching TTPs and the threat landscape and translating that research data into high quality detections. Your role involves actively seeking effective and comprehensive detection strategy and capabilities, ensuring detections are thoroughly tested, alerts are relevant, of value and playbooks are available to and understood by cybersecurity operations teams.
As one of the team’s specialists on cloud technologies, you will work to mature the Attack Analysis team in how we secure, monitor and respond to incidents in both private and public cloud environments. You will work with internal security engineering and cloud engineering teams to ensure that Attack Analysis requirements are represented in the architecture, design and implementation of cloud environments. You'll help design, write and automate detection and incident response processes and tools for public and private cloud environments.
Working in cybersecurity takes passion for technology, speed, a desire to learn, and vigilance in order to keep every asset safe. Working with your internal team, as well as technologists and innovators across our global network, your ability to identify threats, provide intelligent analysis and positive actions will stop crimes and strengthen our data.
As a member of the Attack Analysis team, you will fit into a Global team providing 24/7 monitoring and Incident Response , acting as the frontline for attacks against the firms' infrastructure. As a Detection Engineer, your role will include advanced analysis, threat hunting, evaluation of new security technology as well as ensuring larger technology projects at the company are ready to be integrated into the Attack Analysis team and monitoring function. This could include running training sessions for the team in range or virtual environments, leading hunting exercises, serving as a technical escalation point and coaching the team through adopting monitoring responsibility.
Public/Private Cloud Engineering and Incident Response,Detection Engineering, Threat Modelling.Hands-on experience withat least 1 cloud platform (AWS, Azure, GCP) is required.
6 years of working experience with at least 4 years of hands-on experience in Security Operations and Incident Response or Computer Network Operations (CNO) or Computer Network Defense (CND).
Hands-on experience with at least 1 cloud platform (AWS, Azure, GCP) including infrastructure, security and cloud APIs.
Bachelor’s degree in Computer Science, Information Security, Digital Forensics or equivalent qualification.
Excellent written and verbal communication skills to describe security event details and technical analysis with audiences within the cybersecurity organization and other technology groups.
Ability to research TTPs and develop high fidelity detections in various tools/languages including but not limited to: Splunk, CrowdStrike, Azure Sentinel, Suricata, Snort.
Ability to use data science and analytical skills to identify anomalies over large datasets.
Experience with log analysis and correlation of large datasets from multiple data sources to identify and investigate attack patterns.
Experience with threat hunting on a large, enterprise network both as an individual and leading hunting exercises with other team members.
Ability to perform packet-level analysis and strong understanding of common network protocols and the OSI model.
Experience using scripting languages (Python, Powershell, Bash, etc.) to parse machine-generated data, interact with REST APIs and automate repetitive tasks.
Experience with Digital Forensics & Incident Response processes including memory & file system analysis methodologies.
Experience with analyzing Endpoint Detection & Response (EDR) telemetry and excellent knowledge of operating system internals (Windows, Linux, macOS).
Knowledge with command line tools across Windows and Linux.
Familiarity with malware analysis (both static and dynamic), binary triage, and file format analysis.
Morgan is a global leader in financial services, providing strategic advice and products to the world’s most prominent corporations, governments, wealthy individuals and institutional investors. Our first-class business in a first-class way approach to serving clients drives everything we do. We strive to build trusted, long-term partnerships to help our clients achieve their business objectives.
We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as mental health or physical disability needs. Visit ourFAQs for more information about requesting an accommodation. Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
#



  • London, United Kingdom Cyber Crime Full time

    Senior Threat Detection and Validation Engineer dunnhumby Global leader in Customer data science and analytics, experts in working with brands, grocery retail, retail pharmacy, and retailer financial services. View company page dunnhumby is the global leader in Customer Data Science, empowering businesses everywhere to compete and thrive in the...


  • London, United Kingdom Cyber Crime Full time

    Senior Threat Detection and Validation Engineer dunnhumby Global leader in Customer data science and analytics, experts in working with brands, grocery retail, retail pharmacy, and retailer financial services. View company page dunnhumby is the global leader in Customer Data Science, empowering businesses everywhere to compete and thrive in the...


  • London, United Kingdom Cyber Crime Full time

    Senior Threat Detection and Validation Engineer dunnhumby Global leader in Customer data science and analytics, experts in working with brands, grocery retail, retail pharmacy, and retailer financial services. View company page dunnhumby is the global leader in Customer Data Science, empowering businesses everywhere to compete and thrive in the...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    Senior Cyber Detection Engineer – Cloud Technical Lead You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience who...


  • London, United Kingdom Cyber Crime Full time

    Senior Threat Detection and Validation Engineer Global leader in Customer data science and analytics, experts in working with brands, grocery retail, retail pharmacy, and retailer financial services. dunnhumby is the global leader in Customer Data Science, empowering businesses everywhere to compete and thrive in the modern data-driven economy. With...


  • London, United Kingdom Live Nation (Music) UK Limited Full time

    Cyber Defence Lead Detection Engineer page is loaded Cyber Defence Lead Detection Engineer Apply locations Farringdon, London, United Kingdom time type Full time posted on Posted 2 Days Ago job requisition id JR-63169 Job Summary: Company: Live Nation Entertainment Department: Trust and Security Location: UK, remote Reports to: Senior Manager of...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    Senior Cyber Detection Engineer – Cloud Technical Lead You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    Senior Cyber Detection Engineer – Cloud Technical Lead You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience who...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    Senior Cyber Detection Engineer – Cloud Technical Lead You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    Senior Cyber Detection Engineer – Cloud Technical Lead You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience...

  • Detection Engineer

    2 weeks ago


    London, United Kingdom Trident Search Full time

    Trident Search have partnered with a company who pride themselves on being ahead of the curve when it comes to cyber security. The client works in the financial sector so its vital they remain at the forefront of the industry, to protect their clients data and their funds. They are looking for an autonomous detection engineer to join their global team....


  • London, United Kingdom Stellar Cyber Full time

    Stellar Cyber is a fast-growing Cybersecurity company focused on delivering holistic cyberattack protection to organizations while significantly reducing total costs of ownership with its innovative Open XDR (eXtended Detection and Response) platform based on advanced ML and security technologies. Stellar Cyber has been recognized by Gartner as one of the...


  • London, United Kingdom Digital Waffle Full time

    Job Title: Senior Cyber Security EngineernLocation: Birmingham, UK (Hybrid)nSalary: £65,000 per annumRole Overview:nAs a Senior Cyber Security Engineer, you will play a pivotal role in designing, implementing, and maintaining the cyber security infrastructure. You will utilise Microsoft technologies, including Azure, Sentinel, Defender, and XDR, to ensure...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience who enjoys researching TTPs and the threat landscape and...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience who enjoys researching TTPs and the threat landscape and...


  • London, United Kingdom JPMorgan Chase & Co. Full time

    You will be one of the team's subject matter experts on SIEM as well as cloud technologies. You will help mature how JPMC utilizes multiple SIEM solutions (primarily Splunk) for various use-cases within Cyber Operations. The ideal candidate will be someone with previous SOC and cloud experience who enjoys researching TTPs and the threat landscape and...

  • Cyber Engineer

    11 hours ago


    London, United Kingdom Cyber Crime Full time

    You’re tenacious and driven, so the last place you want to work is some boring bank. We’re not a normal financial services company, constrained by a fixed mindset and legacy systems. We’re an agile business that dreams big and has the resources to deliver big and we were the first major bank to go all in on AWS. Their security is our responsibility...


  • London, United Kingdom TRIA Full time

    Senior Cyber Security Engineer Outside IR35 - Negotiable Flexible working - 1 day per month onsite in London We are representing a global decentralised organisation who are going through tremendous amounts of transformation (over 100 sites, 100,000 users, 14,000 employees). They are looking for an experienced Cyber Security Analyst to help transform...


  • London, United Kingdom Stellar Cyber Inc. Full time

    Stellar Cyber is a fast-growing Cybersecurity company focused on delivering holistic cyberattack protection to organizations while significantly reducing total costs of ownership with its innovative  Open XDR (eXtended Detection and Response) platform  based on advanced ML and security technologies. Stellar Cyber has been recognized by Gartner as one of...


  • London, United Kingdom dunnhumby Full time

    Senior Threat Detection and Validation Engineer dunnhumby Global leader in Customer data science and analytics, experts in working with brands, grocery retail, retail pharmacy, and retailer financial services. View company page dunnhumby is the global leader in Customer Data Science, empowering businesses everywhere to compete and thrive in the...