The Pennymac Information Security department is looking to bring on a Sr. Detection Engineer to drive our Threat Detection and Response efforts. You will specialize in developing sophisticated signatures, queries, alerts, and dashboards to detect and neutralize cyber threats in a complex cloud environment while focusing on the SOC analyst experience. The Sr. Detection Engineer will: Design, develop, test, and deploy high-quality detection rules using version control systems (e.g., Git) and CI/CD pipelines. Drive the overall detection engineering lifecycle including processes, improvements, and innovations. Use inputs from Threat Intelligence (TI) and threat modeling exercises to identify critical detection gaps. Maintain a comprehensive risk detection coverage mapping to communicate current coverage and show improvements. Serve as the primary author and reviewer of new detectors, ensuring proper documentation and testing. Continually observe the performance of existing detectors and tune them to reduce false positives and ensure they remain valuable. Leverage AI/ML capabilities to enhance the detection engineering lifecycle and identify anomalies. Partner with the Security Engineering team to configure, maintain, and optimize security monitoring tools to ensure maximum data ingestion quality and search performance. Incident Response & Operations Support Act as a tier-2 technical escalation point for the L1 SOC, providing expertise in triage, root cause analysis, and remediation planning for complex security alerts. Perform in-depth host and network analysis across various environments with a primary focus on Windows, Cloud (AWS, Azure, GCP), and SaaS technologies. Execute the full IR lifecycle and lead incident handling during major security events. Serve as a technical escalation point for complex or novel security incidents. Develop and review Standard Operating Procedures (SOPs), playbooks, and other documentation for the IR team. Provide thought leadership on strategic objectives such as processes, technologies, and exercises. Mentor and train junior and mid-level incident responders on advanced techniques, tools, and best practices.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed
Number of Employees
5,001-10,000 employees