Threat Detection Engineer II
Sunnyvale, CA, USA
Posted on Saturday, May 13, 2023
The security organization at Uber is dedicated to enabling safe and secure innovation while protecting the communities we serve both online and in the physical world. Our teams are responsible for protecting both people and their data across intersections of the digital and physical world. The primary objective for Uber Engineering Security team is to enable the technical ambitions of the company while maintaining the highest standards of security and privacy for our customers and partners. As cybersecurity threats evolve, so do we. About The RoleWe are seeking a Threat Detection Engineer with technical depth, security intuition, and ambitious spirit to join our Threat Defense & Response team! You'll collaborate with cross-functional teams to build innovative detection strategies and help develop a best-in-class threat detection program. You will help build a larger external threat detection community benefiting security defenders small and large globally. What You'll Do
- Use big data and real-time streaming technologies to build and refine threat detections.
- Build mechanisms that combine multiple detection signals to create higher fidelity threat detections.
- Build and use data platforms and systems to enrich and enhance detection fidelity as well as drive for automated containment.
- Support the Security Response and Investigation team in high impacting events.
- Work cross functionally to perform proactive Threat Hunting and Purple Teaming.
- Bachelor's or Master's degree in a relevant field
- In-depth knowledge of security logging for Linux, macOS, or Windows
- 2+ years of experience building detection logic using security logs to detect malicious activity with high fidelity across a broad set of detection use cases.
- In-depth knowledge of adversary capabilities, infrastructure, and techniques.
- Experience with tools and techniques for analyzing large security datasets
- Experience with at least one programming or scripting language (e.g., Python, Go, Java)
- Experience with Elastic Stack as a security platform
- Experience with Phantom SOAR
- Experience with using Spark, SQL, Lucene, KQL, and Presto
See more open positions at Uber
Something looks off?