Akamai Technologies is a leading company that powers and protects life online. They are seeking a Security Engineer II to design, implement, and optimize SIEM solutions, ensuring the security and integrity of their systems and infrastructure.
Responsibilities:
- Developing, testing, and tuning Kibana Security detection rules, investigating Kibana Security alerts and documenting findings, scope, and recommended actions
- Analyzing telemetry across identity, endpoint, network, and cloud data sources
- Improving alert fidelity through tuning, exception management, and rule lifecycle maintenance
- Mapping detection logic to MITRE ATT&CK and maintaining investigation guidance
- Building dashboards, saved searches, and queries to support investigations and operational visibility
- Partnering with SecOps, IR, IAM, cloud, and infrastructure teams to improve detection coverage and response quality
- Identifying data quality gaps, field mapping issues, and logging deficiencies that affect detection quality
- Utilizing scripting languages like Python, Bash, JavaScript, or PowerShell
Requirements:
- 5 years of experience in security operations, detection engineering, threat detection, or incident response
- Experience with Elastic Security / Kibana or a similar SIEM platform
- Demonstrate experience writing and tuning detections using KQL, EQL, ES|QL, SPL, or similar query languages
- Possess knowledge of common log sources such as authentication, endpoint, network, and cloud audit logs
- Familiarity with cloud security concepts, especially AWS
- Understanding of MITRE ATT&CK, alert triage, and false positive reduction
- Working knowledge of scripting in Python or Bash