Unisys Logo

Unisys

Detection Engineer

Posted 10 Days Ago
Be an Early Applicant
In-Office or Remote
2 Locations
Mid level
In-Office or Remote
2 Locations
Mid level
Develop and implement detection mechanisms, conduct security investigations and threat hunting, manage MSSP operations, and automate security tools.
The summary above was generated by AI

What success looks like in this role:

  • Develop and Implement Custom Detections: 

  • Design, develop, and maintain high-fidelity detection rules, signatures, and analytics for a diverse array of enterprise security tools, including Security Information and Event Management (SIEM) systems, Endpoint Detection and Response (EDR) platforms, and Intrusion Detection Systems (IDS). The objective is to identify both known and emerging threats effectively. 

  • Translate complex threat intelligence, sophisticated attack methodologies (e.g., leveraging the MITRE ATT&CK Framework), and vulnerability insights into precise, actionable, and automated detection logic. 

  • Continuously tune and optimize existing detection mechanisms to significantly reduce false positives, enhance alert fidelity, and ensure a high signal-to-noise ratio, thereby minimizing alert fatigue for security analysts. 

  • Perform Tier 3 Security Investigations and Proactive Threat Hunting: 

  • Lead and conduct advanced, complex security investigations (Tier 3) escalated from lower tiers, encompassing root cause analysis, malware and indicator analysis, and recommending robust corrective measures to prevent future incidents. 

  • Proactively conduct threat hunting activities across network, endpoint, and cloud environments to identify novel or hidden threats, subtle anomalies, and security gaps that may evade existing detection controls. 

  • Collaborate closely with Incident Response (IR) teams to ensure effective communication, facilitate rapid response to detected threats, and integrate lessons learned into the development of new or refined detection capabilities. 

  • Manage and Optimize MSSP Tier 1 & Tier 2 Operations: 

  • Serve as the primary technical liaison for Managed Security Service Provider (MSSP) partners, providing expert guidance and strategic oversight for their Tier 1 and Tier 2 security monitoring and operational activities. 

  • Ensure MSSP adherence to organizational security policies, detection standards, and incident escalation procedures, thereby contributing to the overall security posture. 

  • Collaborate with MSSP teams on detection rule deployment, tuning, and validation, leveraging continuous feedback loops to enhance overall detection efficacy and reduce alert fatigue experienced by their analysts. 

  • Review MSSP-generated alerts and reports, providing constructive feedback and precise technical direction for continuous improvement in their detection and response capabilities. 

  • Security Automation and Tooling: 

  • Develop and maintain automation scripts and tools (e.g., Python, PowerShell, Bash) to streamline security detection operations, facilitate efficient data parsing, integrate disparate security tools, and enhance response capabilities. 

  • Build, design, run, and troubleshoot playbooks within a Security Orchestration, Automation, and Response (SOAR) solution to automate incident response processes and significantly improve operational efficiency. 

  • Documentation and Continuous Improvement: 

  • Maintain comprehensive and up-to-date documentation of detection logic, configurations, incident response procedures, and investigation findings for robust knowledge sharing and auditing purposes. 

  • Stay abreast of the latest security threats, vulnerabilities, attack vectors, industry trends, and emerging security technologies to proactively enhance detection measures and fortify digital boundaries. 

You will be successful in this role if you have:

  • Experience: 2-3 years of hands-on experience working in a Security Operations Center (SOC), Network Operations Center (NOC), Digital Forensics, or Incident Response role, demonstrating a foundational understanding of operational security challenges and the incident lifecycle. 

  • Technical Proficiency: 

  • In-depth understanding and practical experience with Security Information and Event Management (SIEM) systems (e.g., Splunk, LogRhythm, Google SecOps, Elastic) for log analysis, sophisticated rule creation, and dashboard development. 

  • Strong knowledge of Endpoint Detection and Response (EDR) and Intrusion Detection/Prevention Systems (IDS/IPS). 

  • Proficiency in scripting languages (e.g., Python, PowerShell, Bash) for automation, data manipulation, and custom tool development. 

  • Solid understanding of network security, protocols, and traffic analysis. 

  • Familiarity with threat intelligence platforms and frameworks (e.g., MITRE ATT&CK) to inform detection strategy and rule development. 

  • Analytical and Problem-Solving Skills: 

  • Exceptional analytical skills to analyze large, complex datasets, identify subtle anomalies, patterns, and indicators of malicious activity. 

  • Demonstrated ability to think critically, troubleshoot complex problems, and make sound decisions under pressure, particularly during incident investigations. 

  • Collaboration and Communication: 

  • Strong verbal and written communication skills for reporting findings, documenting procedures, and collaborating effectively with cross-functional teams and external partners. 

 

Preferred Qualifications: 

 

  • Experience working with Google Cloud Platform (GCP) security services, audit logs, and cloud-native detection tools. 

  • Hands-on experience with Kubernetes incident response and forensic analysis. 

  • Familiarity with Detection-as-Code principles, version control (e.g., Git/GitHub), and CI/CD pipelines for detection rule management. 

  • Relevant security certifications (e.g., SANS, Offensive Security, cloud security certifications). 

Benefit Highlights:
Unisys offers an outstanding benefits package, featuring unlimited paid time off, a 401(k) match, comprehensive healthcare, HSA matching, ongoing learning opportunities, and more! We’re committed to supporting work-life balance and investing in your future success.

Video Interview Notice:
At Unisys, we incorporate video interviews as a key part of our hiring process. This allows us to get to know you better and provide a more engaging and convenient interview experience. We appreciate your understanding and look forward to connecting with you virtually!

#LI-JV1

This role may require access to export-controlled commodities and technology.  Therefore, to conform to U.S. export control regulations, applicant should be eligible for any required authorizations from the U.S. Government.

Unisys is proud to be an equal opportunity employer that considers all qualified applicants without regard to age, caste, citizenship, color, disability, family medical history, family status, ethnicity, gender, gender expression, gender identity, genetic information, marital status, national origin, parental status, pregnancy, race, religion, sex, sexual orientation, transgender status, veteran status or any other category protected by law.

This commitment includes our efforts to provide for all those who seek to express interest in employment the opportunity to participate without barriers. If you are a US job seeker unable to review the job opportunities herein, or cannot otherwise complete your expression of interest, without additional assistance and would like to discuss a request for reasonable accommodation, please contact our Global Recruiting organization at [email protected] or alternatively Toll Free: 888-560-1782 (Prompt 4).  US job seekers can find more information about Unisys’  EEO commitment here.

Top Skills

Bash
Endpoint Detection And Response (Edr)
Google Cloud Platform
Intrusion Detection Systems (Ids)
Powershell
Python
Security Information And Event Management (Siem)

Similar Jobs

5 Days Ago
In-Office or Remote
Irvine, CA, USA
140K-180K Annually
Senior level
140K-180K Annually
Senior level
Aerospace • Artificial Intelligence • Hardware • Information Technology • Software • Defense • Manufacturing
Develop and optimize missile detection algorithms, implement ML models for imagery analysis, and collaborate with engineers on validation and data analysis.
Top Skills: C++OnnxOpencvPythonPyTorchTensorFlow
10 Days Ago
Remote or Hybrid
CA, USA
135K-215K Annually
Senior level
135K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The role involves researching, developing, and delivering vulnerability detection capabilities for CrowdStrike, collaborating with teams on technical solutions and product requirements.
Top Skills: GoPerlPython
6 Days Ago
Remote
USA
148K-175K Annually
Mid level
148K-175K Annually
Mid level
Security • Cybersecurity
The Software Engineer II will build and optimize backend systems for a Detection Engine, focusing on data analysis and feature extraction to improve detection efficacy.
Top Skills: Distributed SystemsGoMl SystemsPython

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account