Concordant, LLC is a leading provider of specialized Cybersecurity solutions to the Federal Government and commercial clients. They are seeking an experienced Security Analyst with a strong background in detection engineering to support enterprise security operations, focusing on developing detection logic and improving threat visibility.
Responsibilities:
- Develop and maintain detection rules using Sigma, Yara, and similar frameworks
- Build and tune threat detection logic for enterprise environments
- Leverage scripting to automate detection engineering processes
- Map detections to MITRE ATT&CK techniques and tactics
- Analyze Windows and Linux artifacts to improve detection coverage
- Support security monitoring and incident response teams
- Continuously improve detection quality and reduce false positives
- Document detection logic, use cases, and operational procedures
Requirements:
- Bachelor's degree in Information Technology, Information Security, or related field
- 8+ years of relevant work experience in security architecture may be substituted in lieu of education
- 5+ years of experience with scripting and automation (Python, Bash, PowerShell, or similar)
- 5+ years of experience supporting large IT environments and/or system deployments
- Experience with Sigma, Yara, and other industry-standard detection languages
- Experience working with the MITRE ATT&CK framework
- CISSP, CISA, CISO, or equivalent advanced security certifications (CEH, OSCP, GPEN)
- Vendor certifications in detection engineering
- Experience with Palo Alto Cortex XSIAM platform
- Deep understanding of Windows and Linux artifacts
- Candidates local to Columbia, South Carolina or surrounding areas preferred