Principal Security Analyst and Research Engineer
Company: Splunk
Location: San Jose
Posted on: March 17, 2023
|
|
Job Description:
Join us as we pursue our disruptive new vision to make machine
data accessible, usable and valuable to everyone. We are a company
filled with people who are passionate about our product and seek to
deliver the best experience for our customers. At Splunk, we're
committed to our work, customers, having fun and most importantly
to each other's success. Learn more about Splunk careers and how
you can become a part of our journey!
Are you passionate about working on products that have a positive
impact on the technology world? Do you enjoy building large scale
applications that are running on huge data sets? Do you value
working in an environment where you're empowered to make key
technical decisions across a full stack of technologies? If so, a
role on the Security Applications Engineering team could be a great
fit for you.
Role
As a Principal-level Security Analyst and Research Engineer, you
will join our Splunk Attack Analyzer Team (the artist formerly
known as TwinWave) in developing detections for our
industry-leading, microservice-based threat analysis pipeline. You
can contribute as a utility player (you enjoy creating detections
for a wide range of threats using a wide range of technologies) or
as an expert (creating detections and detection technologies) in
one of the following areas:
Phishing
Windows Sandboxing
Our team is a combination of individuals whose skills/roles range
from a pure developer, to an analyst, to a researcher, to something
in between. We believe that you should be able to choose your own
adventure and figure out the best way to provide relevant and
timely detections to our customers. We try to allow you to play to
your strengths, while improving upon areas of opportunity. If a
good day to you means causing miscreants to have a bad one, joining
our jovial band of talented and dedicated detection engineers might
be just the role you are looking for!
Responsibilities
As a Security Analyst and Researcher, you will keep abreast of the
current threat landscape and implement detections to protect our
customers.
You will work closely with the developers on the team to identify
issues, missing features, and feature enhancements in detection
techniques, detection engines, and automation.
Qualifications
5+ years of demonstrated ability as a detection engineer, security
researcher, or threat analyst.
Bachelor's degree in Computer Science or another quantitative
field. Equivalent education and/or experience will be
considered.
Ability to write detections for a variety of modern threats:
phishing, malware, and exploits (Regex, Yara, ClamAV, Suricata,
Sigma, Behavioral-based (Sandbox such as Cuckoo/CAPE)).
Knowledge, Skills, and Abilities
Understanding of the modern threat landscape facing Enterprise
environments today.
Ability to create complex regular expressions for detection
purposes.
Proficiency with Golang or Python.
Proficiency with JSON.
Excellent verbal and written communication skills.
Nice To Haves
Familiarity with modern web-based phishing tactics.
Understanding of typical Phishkit structure.
Understanding of Microsoft Office file formats and how they can be
abused for the delivery of threats.
Knowledge of commonly abused windows file formats (chm, hta, xlst,
vbs, bat, html, csv, and others).
Knowledge of Windows internals, hooking techniques, and
Sandbox-based detections.
Ability to reverse engineer malicious Windows executables.
Experience writing file format parsers using RFC's, Microsoft file
format specifications.
Knowledge of commonly used and abused network protocols (HTTP, FTP,
SMTP).
Knowledge of the MITRE ATT&CK Framework and additional relevant
attacker TTP's.
What We Offer You
A constant stream of new things for you to learn. We're always
expanding into new areas, bringing in open-source projects and
contributing back, and exploring new technologies.
A set of exceptionally talented and dedicated peers, all the way
from engineering to customer support.
Growth and mentorship. We believe in growing engineers through
ownership and leadership opportunities. We also believe mentors
help both sides of the equation.
A stable, collaborative and supportive work environment.
Fun. It is one of our core tenets.
Work life balance, with efficient work from home environments today
and modern offices standing by for future times.
We value diversity at our company. All qualified applicants will
receive consideration for employment without regard to race, color,
religion, sex, sexual orientation, gender identity, national
origin, or any other applicable legally protected characteristics
in the location in which the candidate is applying.
For job positions in San Francisco, CA, and other locations where
required, we will consider for employment qualified applicants with
arrest and conviction records.
We will ensure that individuals with disabilities are provided
reasonable accommodation to participate in the job application or
interview process, to perform crucial job functions, and to receive
other benefits and privileges of employment. Please contact us to
request accommodation.
Note: Splunk provides flexibility and choice in the working
arrangement for most roles, including remote and/or in-office
roles. We have a market-based pay structure which varies by
location. Please note that the base pay range is a guideline and
for candidates who receive an offer, the base pay will vary based
on factors such as work location as set out below, as well as the
knowledge, skills and experience of the candidate. In addition to
base pay, this role is eligible for incentive compensation and
benefits, and may be eligible for equity.
Benefits are an important part of Splunk's Total Rewards package.
This role is eligible for a competitive benefits package which
includes medical, dental, vision, a 401(k) plan and match, paid
time off, an ESPP and much more! Learn more about our comprehensive
benefits and wellbeing offering here
(https://splunkbenefits.com/int) .
Base Pay Range
SF Bay Area, Seattle Metro, and New York City Metro Area
Base Pay Range: $180,800 - 248,600 per year
California (excludes SF Bay Area), Washington (excludes Seattle
Metro), Washington DC Metro, and Massachusetts
Base Pay Range: $171,200 - 235,400 per year
All other cities and states excluding California, Washington,
Massachusetts, New York City Metro Area and Washington DC Metro
Area.
Base Pay Range: $153,600 - 211,200 per year
About Splunk
Splunk was founded to pursue a disruptive new vision: make machine
data accessible, usable and valuable to everyone. Machine data is
one of the fastest growing and most complex areas of big
data-generated by every component of IT infrastructures,
applications, mobile phone location data, website clickstreams,
social data, sensors, RFID and much more.
Splunk is focused specifically on the challenges and opportunity of
taking massive amounts of machine data, and providing powerful
insights from that data. IT insights. Security insights. Business
insights. It's what we call Operational Intelligence.
Since shipping its software in 2006, Splunk now has over 13,000
customers in more than 110 countries around the world. These
organizations are using Splunk to harness the power of their
machine data to deepen business and customer understanding,
mitigate cybersecurity risk, prevent fraud, improve service
performance and reduce costs. Innovation is in our DNA - from
technology to the way we do business. Splunk is the platform for
Operational Intelligence!
Splunk has more than 2,700 global employees, with headquarters in
San Francisco, an office in San Jose, CA and regional headquarters
in London and Hong Kong.
We've built a phenomenal foundation for success with a proven
leadership team, highly passionate employees and unique patented
software. We invite you to help us continue our drive to define a
new industry and become part of an innovative, and disruptive
software company.
Benefits & Perks: Wow! This is really cool!
SF Only
Medical, full company paid Dental, Vision and Life Insurance,
Flexible Spending and Dependent Care Accounts, Commuter Accounts,
Employee Stock Purchase Plan (ESPP), 401(k), 3 weeks of PTO, sick
leave, stocked micro kitchens in Splunk offices, catered lunches on
Mondays, catered breakfast on Fridays, basketball hoops, ping pong,
arcade games, BBQ's, soccer, "Fun Fridays".
Pursuant to the San Francisco Fair Chance Ordinance, we will
consider for employment qualified applicants with arrest and
conviction records.
Non SF
Medical, full company paid Dental, Vision and Life Insurance,
Flexible Spending and Dependent Care Accounts, Commuter Accounts,
Employee Stock Purchase Plan (ESPP), 401(k), 3 weeks of PTO and
sick leave. Our work environments vary by location however we
believe in hosting amenities and fun activities to fuel our energy.
You may find fully stocked micro kitchens, catered lunches on
Mondays and breakfast on Fridays, basketball hoops, ping pong,
arcade games, BBQ's, soccer and "Fun Fridays".
This isn't a job - it's a life changer - are you ready?
Individuals seeking employment at Splunk are considered without
regards to race, religion, color, national origin, ancestry, sex,
gender, gender identity, gender expression, sexual orientation,
marital status, age, physical or mental disability or medical
condition (except where physical fitness is a valid occupational
qualification), genetic information, veteran status, or any other
consideration made unlawful by federal, state or local laws. Click
here to review the US Department of Labor's EEO is The Law notice.
Please click here to review Splunk's Affirmative Action Policy
Statement.
Splunk does not discriminate against employees or applicants
because they have inquired about, discussed, or disclosed their own
pay or the pay of another employee or applicant. Please click here
to review Splunk's Pay Transparency Nondiscrimination
Provision.
Splunk is also committed to providing access to all individuals who
are seeking information from our website. Any individual using
assistive technology (such as a screen reader, Braille reader,
etc.) who experiences difficulty accessing information on any part
of Splunk's website should send comments to
accessiblecareers@splunk.com. Please include the nature of the
accessibility problem and your e-mail or contact address. If the
accessibility problem involves a particular page, the message
should include the URL of that page.
Splunk doesn't accept unsolicited agency resumes and won't pay fees
to any third-party agency or firm that doesn't have a signed
agreement with Splunk.
To check on your application click here.
Keywords: Splunk, San Jose , Principal Security Analyst and Research Engineer, Engineering , San Jose, California
Click
here to apply!
|