Build, refine, and manage detection content to identify and mitigate potential threats.
Develop a Detection-as-Code standard using code repositories and CI/CD pipelines to streamline content deployment via Infrastructure-as-Code methodologies.
Work closely with various teams in Security Operations to anticipate and detect potential threats before they fully materialize.
Participate in continuous improvement initiatives to enhance detection capabilities and efficiency.
Develop and maintain documentation for detection logic, use cases, and response playbooks.
Maintain up-to-date knowledge of the latest cybersecurity threats, tools, and best practices.
Contribute to automation of detection and response processes using SOAR platforms.
Requirements
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
2+ years of experience in cybersecurity, preferably in detection engineering, threat hunting, or incident response
Proficiency in writing and tuning detection logic in SIEM platforms (e.g., Splunk, Sentinel, Elastic).
Strong understanding of cybersecurity principles, including SIEM, IDS/IPS, and endpoint detection and response (EDR) solutions.
Experience with coding/scripting languages such as Python, PowerShell, or Bash.
Familiarity with CI/CD pipelines, code repositories (e.g., Git), and Infrastructure-as-Code tools (e.g., Terraform, Ansible).
Excellent problem-solving skills and attention to detail.
Strong communication and documentation abilities.
Experience in a cloud environment (e.g., AWS, Azure, GCP).
Knowledge of malware analysis, reverse engineering, and digital forensics.
Experience with performing insider threat analysis and detections
Knowledge of security orchestration and automation platforms
Relevant certifications such as GCDA, GCFA, or equivalent.
Salary Range:
$88,900 - 151,100 USD
Working with Us:
As a Northern Trust partner, greater achievements await. You will be part of a flexible and collaborative work culture in an organization where financial strength and stability is an asset that emboldens us to explore new ideas.
Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to assisting the communities we serve! Join a workplace with a greater purpose.
We'd love to learn more about how your interests and experience could be a fit with one of the world's most admired and sustainable companies! Build your career with us and apply today. #MadeForGreater
Reasonable accommodation
Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com .
We hope you're excited about the role and the opportunity to work with us. We value an inclusive workplace and understand flexibility means different things to different people.
Apply today and talk to us about your flexible working requirements and together we can achieve greater.
Benefits
Health insuranceDental insuranceVision insurance401(k)Flexible scheduleEquity / stock optionsPerformance bonusParental leave
Additional Information
About Northern Trust:
Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.
Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring principles of service, expertise, and integrity. With more than 130 years of financial experience and over 22,000 partners, we serve the world's most sophisticated clients using leading technology and exceptional service.
Position Overview:
The Detection Engineer will play a crucial role in our cybersecurity team by developing and refining detection content to safeguard our digital assets. The ideal candidate will be responsible for developing, tuning, and maintaining advanced detection mechanisms across our security platforms.