Security Engineering Skills
Threat Led:
• Ability to assess and validate information from various sources on cyber and
informational security threats to business
• Ability to break down and translate information into tangible actionable data.
Secure & Test-Driven Engineering
• Aware of cyber security threat frameworks such as MITRE ATT&CK, Lockheed
Martin Killchain etc.
• Ability to specify/implement processes to maintain required level of security for a
component/product/system during its lifecycle.
• Contribute to security evaluation of threat/vulnerabilities faced by
systems.
• Applies recognised evaluation/testing methodologies, tools and techniques to existing detection content reviews, suggesting improvements where appropriate.
Research:
• Ability to quantify and define research goals to generate worthwhile relevant detection
ideas for further testing and exploration.
• Ability to summarise findings or technical information to be disseminated with wider
teams, factoring in business knowledge and the audience.
Experience relevant for this role:
• An ability to develop queries and enable robust detection of threats.
• Working knowledge of Windows, macOS or Linux operating systems
• Ability to work independently as well as part of a team.
• Awareness of modern attacker TTPs
• Translate threat intelligence into actionable searches & recommendations.
• A broad understanding of detection technologies such as SIEM, EDR, etc
• A broad understanding of security concepts; an interest and passion for cyber security
• An analytical approach; ability in problem solving and comfortable working on
production systems at scale.
• Query languages such as KQL, SPL, SQL, etc
Desirable Skills and Experience:
• Knowledge of cloud infrastructure, cloud security and cloud APIs a plus
• Knowledge of attacker tools and evasion techniques within offensive engineering
• Working knowledge of at least one major programming language, including scripting
languages like Python and PowerShell
• Experience of developing detections
• Experience of using version control systems (e.g. Github) for code maintenance