Talent.com
Lead Threat Detection Engineer

Lead Threat Detection Engineer

McKessonIrving, TX, United States
7 hours ago
Job type
  • Full-time
Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you.

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection capabilities and tools. This team is responsible for building detection content, enabling integration, automation, enrichment, and performance of alerts. This role enables speed, quality, and coverage of threats for security operations and reduces risk to McKesson business operations.

Position Description / Responsibilities

  • Mature from a manual detection practice to a modern, automated, and standardized Detection-as-Code practice and infrastructure.
  • Develop use-cases based on intelligence, red team results, and incident data
  • Develop IOC workflows and a feedback loop for the Threat Intel Platform (TIP)
  • Write detection and correlation rules to identify threats across our stack
  • Assist in onboarding logs and identifying gaps in logs or alert results
  • Develop a deep understanding of data models, macros, indexes, sources, and field alias and the technology foundation our detection stack is built
  • Understand data schema / API standards, automation, and messaging systems
  • Bring a metrics-driven mindset to our rules, signals (IOCs), and alerts

Critical Requirements

  • Prioritize detection use-case and scope and create a logical rule
  • Ability to prioritize decisions to either write a rule and / or tune a tool / policy
  • Practical experience with threat Actor tracking, tactics, tools, and techniques and working closely with Intel, SOC, and Red Teams (Purple Teams)
  • Ability to measure detection coverage across common frameworks (e.g. NIST CSF, MITRE, KC) and simplify rules and configurations to optimize alerts
  • Ability to automate tasks via scripting, automating inputs and outputs of APIs, and programming skills such as python to enable detection engineering tasks
  • Exceptional interpersonal, organizational, and communication skills and ability to internalize and exemplify Mckesson core values.
  • Splunk SPL knowledge and SIEM experience or additional SIEM background
  • Following Qualifications would be advantageous :

  • 10+ years of professional experience in two or more domains, including : detection engineering, data engineering, incident response, threat hunting, threat intelligence.
  • Bachelor's degree in computer science, Information Security, Security Engineering, Statistics, or Data Science
  • Chronicle Experience, Splunk Certifications (1,2), Automation certifications (Security with Python SEC573), Sigma Rules
  • We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, pleaseclick here.

    Our Base Pay Range for this position

    $139,000 - $231,600

    McKesson is an Equal Opportunity Employer

    McKesson provides equal employment opportunities to applicants and employees and is committed to a diverse and inclusive environment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age or genetic information. For additional information on McKesson's full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

    Join us at McKesson!

    Create a job alert for this search

    Detection Engineer • Irving, TX, United States

    Related jobs
    • Promoted
    • New!
    Threat Modelling Engineer

    Threat Modelling Engineer

    ApTaskDallas, TX, United States
    Full-time
    Title : Threat Modelling Engineer.We are seeking an ideal candidate with 8+ years of experience in a range of technologies and processes, including : . Proficiency in GCP - essential.Strong knowledge o...Show moreLast updated: 7 hours ago
    • Promoted
    Engineer III - Insider Threat

    Engineer III - Insider Threat

    AmerisourceBergen CorporationCarrollton, TX, United States
    Full-time
    Conduct advanced investigations into potential insider threat activities, including data exfiltration, misuse of systems, fraud, and policy violations. Analyze behavioral indicators, user activity l...Show moreLast updated: 2 days ago
    • Promoted
    Threat Engineer

    Threat Engineer

    Diverse LynxPlano, TX, United States
    Full-time
    In depth engineering experience in Threat solutions, including the design, low level engineering, and delivery of new hardware systems for client applications. Experience building / operating / deployin...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior IAM Security Engineer-Dallas / Fort Worth TX

    Senior IAM Security Engineer-Dallas / Fort Worth TX

    Staffing the UniverseDallas, TX, United States
    Full-time
    Location : Dallas / Fort Worth TX Duration : Contract Rate : DOE The first 2-3 weeks will be 100% on site with team members. Candidates will be required and must agree to work on-site 50% of the time a...Show moreLast updated: 7 hours ago
    • Promoted
    • New!
    Senior Cyber Threat Intelligence Engineer (Remote)

    Senior Cyber Threat Intelligence Engineer (Remote)

    USAA CareersPlano, TX, United States
    Remote
    Full-time
    At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military...Show moreLast updated: 7 hours ago
    • Promoted
    • New!
    Security Engineer

    Security Engineer

    TXSEDallas, TX, United States
    Full-time
    We're looking for a Security Engineer who's excited to work across the full security stack.You'll help us stand up and mature key capabilities-including Vulnerability Management, Endpoint Security,...Show moreLast updated: 7 hours ago
    • Promoted
    Security Engineer

    Security Engineer

    iconectivRichardson, TX, United States
    Full-time
    Location - Hybrid - Richardson, TX.Your business and your customers need to confidently access and exchange information simply, seamlessly and securely. In fact, more than 5K customers rely on our d...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Threat Hunter / Detection Engineer

    Threat Hunter / Detection Engineer

    Elevance HealthGrand Prairie, TX, United States
    Full-time
    Threat Hunter / Detection Engineer.Threat Hunter / Detection Engineer.This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexib...Show moreLast updated: 7 hours ago
    • Promoted
    • New!
    Senior Security Engineer

    Senior Security Engineer

    AkkodisPlano, TX, United States
    Full-time
    Responsibilities include designing and deploying advanced cybersecurity platforms and ensuring zero-impact delivery of threat mitigation systems across the network. The rate may be negotiable based ...Show moreLast updated: 7 hours ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    iconectivRichardson, TX, United States
    Full-time
    Location - Hybrid - Richardson, TX.Your business and your customers need to confidently access and exchange information simply, seamlessly and securely. In fact, more than 5K customers rely on our d...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Threat Detection Manager / Hands On / Remote

    Threat Detection Manager / Hands On / Remote

    Motion RecruitmentDallas, TX, United States
    Remote
    Full-time
    A SaaS company in the insurance space is looking to hire a Manager of Threat Detection to join their growing team! They build SaaS products in the insurance space so ideal candidates have experienc...Show moreLast updated: 7 hours ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Diverse LynxPlano, TX, United States
    Full-time
    Lead global initiatives to create and transform infrastructure solutions across the threat prevention space.Interacts externally with key vendors to understand future technological direction and dr...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Security Engineer

    Security Engineer

    Insight GlobalDallas, TX, United States
    Full-time
    Insight Global is seeking a Security Engineer to join one of their utility clients in the DFW area.This individual will play a key role in monitoring, analyzing, and responding to security threats ...Show moreLast updated: 7 hours ago
    • Promoted
    enior Security Engineer

    enior Security Engineer

    Diverse LynxPlano, TX, United States
    Full-time
    Threat Prevention ArchitectRole Summary : Lead global initiatives to create and transform infrastructure solutions across the threat prevention space. Interacts externally with key vendors to understa...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior CyberSecurity Engineer in Dallas

    Senior CyberSecurity Engineer in Dallas

    Energy Jobline ZRDallas, TX, United States
    Full-time
    Shape a remarkable future with us.Build a career working for an industry leader that truly invests in their people and equips them with leading technology, continuous learning, and the ability to b...Show moreLast updated: 7 hours ago
    • Promoted
    Lead Security Engineer - Purple Team (Dallas Ft Worth Metro)

    Lead Security Engineer - Purple Team (Dallas Ft Worth Metro)

    GartnerIrving, TX, United States
    Full-time
    Hiring near our Irving, TX Center of Excellence with a flexible environment.Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients.W...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Security Engineer III - Threat Intelligence

    Security Engineer III - Threat Intelligence

    JPMorgan Chase Bank, N.A.Plano, TX, United States
    Full-time
    Your seniority as a security engineer puts you in the ranks of the top talent in your field.Play a critical role at one of the world's most iconic financial institutions where security is vital.As ...Show moreLast updated: 7 hours ago
    • Promoted
    • New!
    Senior Insider Threat Engineer

    Senior Insider Threat Engineer

    AmerisourceBergen CorporationHebron, TX, United States
    Full-time
    Join our dedicated team at Cencora, where we strive to create healthier futures for people and animals worldwide.We believe that each member of our team is essential in fulfilling our mission.If yo...Show moreLast updated: 7 hours ago