Security Engineer III
Job description
About the role
Anaplan is on the lookout for a talented Security Engineer III to become an integral part of our Security Operations team. This role is pivotal in bolstering our capabilities in threat detection, investigation, and response. You will play a crucial role in merging engineering principles with operational practices, transforming security challenges into scalable and automated solutions that enhance our overall security posture.
Key facts
What you'll do
- Assume responsibility for managing our Security Information and Event Management (SIEM) platform, overseeing the onboarding of log sources, developing parsers, and ensuring the efficiency of data pipelines for effective detection and investigation.
- Design and maintain a comprehensive library of high-quality detection rules utilizing a Detection as Code methodology, which includes version control and automated testing to ensure reliability and accuracy.
- Create automated workflows and playbooks using Security Orchestration, Automation, and Response (SOAR) platforms to streamline alert triage and improve response times.
- Explore the integration of artificial intelligence and machine learning technologies to enhance security operations, focusing on threat intelligence analysis and incident response strategies.
- Incorporate threat intelligence from multiple sources into our detection frameworks and operational workflows to provide timely and actionable insights.
- Engage in proactive threat hunting activities to uncover undetected malicious activities, documenting findings to refine and enhance detection capabilities.
- Offer engineering support during security incidents, assisting in investigations and recovery efforts, and participating in post-incident reviews to identify areas for improvement.
- Collaborate with cross-functional teams to ensure security considerations are integrated throughout the development lifecycle, promoting a culture of security awareness and best practices.
Requirements
- A solid background in security engineering, DevSecOps, or a related field, with significant experience in securing cloud-native environments and contemporary applications.
- Demonstrated expertise in developing and refining SIEM detections, along with active participation in incident response initiatives.
- Familiarity with various security operations tools, including SIEM platforms like Splunk or Microsoft Sentinel, endpoint detection and response (EDR/XDR) solutions, and vulnerability assessment tools.
- Knowledge of threat intelligence platforms and methodologies, coupled with a proactive mindset towards threat hunting activities.
- Proficiency in scripting or programming languages such as Python, Go, or Bash, which are essential for automation and the development of security tools.
- A strong understanding of secure development practices, with the ability to work collaboratively with developers on security-related issues.
- Awareness of security frameworks such as NIST Cybersecurity Framework (CSF) and CIS Benchmarks, along with compliance standards like SOC 2 or ISO 27001.
- Excellent communication skills to articulate complex technical security concepts to various stakeholders and foster collaborative teamwork.
- Experience in incident response and digital forensics, including investigative techniques and conducting post-incident analyses to derive lessons learned.
Nice to have
- Familiarity with forensic tools and methodologies that can aid in investigations and enhance incident response capabilities.
- Experience in working with cloud security solutions and understanding their implications on security operations.
- Knowledge of regulatory requirements and industry standards relevant to security practices.
Skills & tools
- Proficient in SIEM platforms such as Splunk and Microsoft Sentinel
- Experienced with EDR/XDR solutions
- Knowledgeable in threat intelligence platforms like MISP and Recorded Future
- Skilled in scripting languages, including Python, Go, and Bash
- Familiar with security frameworks such as NIST CSF and CIS Benchmarks
Practical notes
At Anaplan, we prioritize diversity and are dedicated to fostering an inclusive workplace for all employees. We are committed to providing reasonable accommodations for individuals with disabilities throughout the application and interview process. If you require assistance, please do not hesitate to reach out.
Anaplan takes recruitment fraud seriously. We do not issue job offers without a comprehensive interview process and will never send offers via email. All official communications will come from an @anaplan.com email address. If you suspect any fraudulent activity, please contact us for verification.