Sporty
Purple Operations Engineer
УдалённоEMEAВ архиве
- Роль
- Безопасность
Зарплата не указана
Проверьте доступность
Доступно для: Anywhere in EMEA. Укажите, откуда вы работаете, чтобы проверить доступность.
Коротко по делу
Security engineer to tune EDR, SIEM, and XDR platforms for high-quality alerts. Requires experience with detection logic (KQL, Sigma, etc.) and scripting (Python, PowerShell). Must understand endpoint, identity, cloud, network, and web attack behaviors.
Ключевые навыки
EDRSIEMXDR
Обязательные навыки
KQLSPLEQLLuceneSigmaYARAPythonPowerShellBashMITRE ATT&CKAtomic Red TeamCalderaVectrTheHiveJiraConfluenceGitHubGitLabosquerySysmonZeekSuricataAWS CloudTrailGuardDutyAzureEntra IDGoogle WorkspaceOktaCloudflareKubernetes logs
Желательные навыки
Microsoft Defender XDRCrowdStrike FalconSentinelOneMicrosoft SentinelSplunk Enterprise SecurityElastic SecurityGoogle SecOps
Обязательные языки
English
| Operations Manager, PaymentsEMEA |
|---|
| Business Development Manager - Communications & Growth PartnershipsEMEA - Remote |
|---|
| Performance Marketing Lead EMEA - Remote |
|---|
| User Acquisition DirectorGlobal - Remote |
| PR CoordinatorMadrid |
|---|
| Sports Presenter / JournalistSpain |
| Video EditorCape Town |
| Social Media Designer JRSão Paulo |
|---|
| Audio OperatorSão Paulo |
|---|
| Projects & Strategy AnalystSão Paulo |
| Video EditorSão Paulo |
| Regional Lobby ManagerSão Paulo |
|---|
| Customer Success BR & MXSão Paulo |
|---|
| INT VIP Account Manager (Hybrid)Cape Town |
|---|
| ZA Affiliate AssociateCape Town |
| ZA Operations Associate- Night ShiftCape Town |
| ZA Retention SpecialistSouth Africa - Remote |
| ZA Risk & Fraud AnalystCape Town |
| BR Payments Ops SpecialistSão Paulo |
|---|
| Operations Director, PaymentsGlobal - Remote |
| Product ManagerBrazil - Remote |
|---|
| Data Analyst (Europe)Europe - Remote |
|---|
| Data Scientist (Europe, Asia)Global - Remote |
| Senior Games Data Analyst (Europe, Asia)Global - Remote |
| EU Product ManagerEurope - Remote |
|---|
| Project ManagerGlobal - Remote |
|---|
| Junior Accountant NewMadrid |
|---|
| Backend Software Engineering Team LeadEurope - Remote |
|---|
| Frontend EngineerGlobal - Remote |
| Frontend Engineer (Latin America)LATAM - Remote |
| Senior Backend EngineerGlobal - Remote |
| Senior QA EngineerGlobal - Remote |
| Python EngineerEurope - Remote |
|---|
| Weekend Backend EngineerGlobal - Remote |
| Database Reliability EngineerEurope - Remote; LATAM - Remote |
|---|
| Site Reliability EngineerEMEA |
| Weekend Site Reliability EngineerGlobal - Remote |
| Lead Hybrid QA Engineer Europe - Remote |
|---|
| Frontend Engineering Team LeadEurope - Remote |
|---|
| Analytics Implementation ConsultantEurope - Remote |
|---|
| Frontend Engineering Team Lead - MarTechEurope - Remote |
| Offensive Security EngineerEurope - Remote |
|---|
| Security Platform EngineerEurope - Remote |
| Interested in working for Sporty?GLOBAL |
|---|
Чем предстоит заниматься
- Tune EDR, SIEM, and XDR detections to reduce false positives and improve alert quality.
- Build and maintain detection rules, correlation searches, dashboards, watchlists, and response workflows.
- Translate Red Team, Purple Team, incident, and Threat Intelligence findings into repeatable defensive checks.
- Validate that EDR policies, prevention rules, logging, sensor health, and response actions work as expected.
- Review noisy alerts and tune thresholds, exclusions, lookups, entity context, and suppression logic.
- Support SOC analysts with clear alert descriptions, triage steps, severity logic, and escalation guidance.
- Improve log coverage, parsing, field normalization, enrichment, and data quality.
- Map detections to MITRE ATT&CK where useful.
- Write portable detection content using formats such as Sigma, which is designed as a generic signature format for SIEM detections.
- Track detection gaps, false positive trends, alert health, and platform performance
Что требуется
- Experience tuning EDR, SIEM, XDR, or SOC monitoring platforms.
- Strong understanding of endpoint, identity, cloud, network, and web attack behaviors.
- Practical experience writing detection logic in KQL, SPL, EQL, Lucene, Sigma, YARA, or similar.
- Familiarity with MITRE ATT&CK mapping and detection coverage analysis.
- Ability to turn Red Team, Purple Team, and incident findings into clear detection logic.
- Experience reducing false positives through rule tuning, exceptions, automation, and better entity context.
- Microsoft Sentinel supports this through automation rules and analytics rule changes.
- Strong scripting ability in Python, PowerShell, Bash, or similar.
- Good understanding of SOC workflows, incident triage, escalation, and response playbooks.
- Strong documentation skills.
Преимущества
- Sporty is a remote first company in pursuit of sustainability
- A competitive salary + individual performance based bonuses every quarter
- 28 days paid annual leave
- Our core working hours are 10am-3pm in your local time zone with flexibility outside of this
- Referral bonuses & flash bonuses
- Top of the line equipment
- Annual company retreats to provide great internal networking opportunities
MarTech
Зарплата не указана