Talent.com
Lead Threat Detection Engineer
Lead Threat Detection EngineerMcKesson • Irving, TX, United States
Lead Threat Detection Engineer

Lead Threat Detection Engineer

McKesson • Irving, TX, United States
18 days ago
Job type
  • Full-time
Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you.

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection capabilities and tools. This team is responsible for building detection content, enabling integration, automation, enrichment, and performance of alerts. This role enables speed, quality, and coverage of threats for security operations and reduces risk to McKesson business operations.

Position Description / Responsibilities

  • Mature from a manual detection practice to a modern, automated, and standardized Detection-as-Code practice and infrastructure.
  • Develop use-cases based on intelligence, red team results, and incident data
  • Develop IOC workflows and a feedback loop for the Threat Intel Platform (TIP)
  • Write detection and correlation rules to identify threats across our stack
  • Assist in onboarding logs and identifying gaps in logs or alert results
  • Develop a deep understanding of data models, macros, indexes, sources, and field alias and the technology foundation our detection stack is built
  • Understand data schema / API standards, automation, and messaging systems
  • Bring a metrics-driven mindset to our rules, signals (IOCs), and alerts

Critical Requirements

  • Prioritize detection use-case and scope and create a logical rule
  • Ability to prioritize decisions to either write a rule and / or tune a tool / policy
  • Practical experience with threat Actor tracking, tactics, tools, and techniques and working closely with Intel, SOC, and Red Teams (Purple Teams)
  • Ability to measure detection coverage across common frameworks (e.g. NIST CSF, MITRE, KC) and simplify rules and configurations to optimize alerts
  • Ability to automate tasks via scripting, automating inputs and outputs of APIs, and programming skills such as python to enable detection engineering tasks
  • Exceptional interpersonal, organizational, and communication skills and ability to internalize and exemplify Mckesson core values.
  • Splunk SPL knowledge and SIEM experience or additional SIEM background
  • Following Qualifications would be advantageous :

  • 10+ years of professional experience in two or more domains, including : detection engineering, data engineering, incident response, threat hunting, threat intelligence.
  • Bachelor's degree in computer science, Information Security, Security Engineering, Statistics, or Data Science
  • Chronicle Experience, Splunk Certifications (1,2), Automation certifications (Security with Python SEC573), Sigma Rules
  • We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.

    Our Base Pay Range for this position

    $139,000 - $231,600

    McKesson is an Equal Opportunity Employer

    McKesson provides equal employment opportunities to applicants and employees and is committed to a diverse and inclusive environment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age or genetic information. For additional information on McKesson's full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

    Join us at McKesson!

    Create a job alert for this search

    Detection Engineer • Irving, TX, United States

    Related jobs
    Cybersecurity Engineer - Vulnerability Management and Application Security

    Cybersecurity Engineer - Vulnerability Management and Application Security

    GM Financial • Arlington, TX, United States
    Full-time
    Opportunity to work in a hybrid model : Potential to work 4 days onsite and 1 day remote.Why GM Financial Cybersecurity?. Innovation isn't just a talking point at GM Financial, it's how we operate.By...Show more
    Last updated: 7 days ago • Promoted
    Senior Director - Catastrophe Management Analytics

    Senior Director - Catastrophe Management Analytics

    Aon • Farmers Branch, TX, United States
    Full-time +1
    Aon is looking for a Senior Director - Catastrophe Modeling - Boston, NYC, Bloomington, Atlanta, Dallas or Chicago.Senior Director of Catastrophe Risk Management. As part of the Catastrophe Manageme...Show more
    Last updated: 30+ days ago • Promoted
    Level II - Certified Surgical Technologist

    Level II - Certified Surgical Technologist

    Baylor Scott & White Health • Waxahachie, TX, United States
    Full-time
    Baylor Scott & White Health is seeking a Certified Surgical Technologist Level II for a job in Waxahachie, Texas.Job Description & Requirements. Certified Surgical Technologist.Location : Baylor, Sc...Show more
    Last updated: 10 days ago • Promoted
    Security Engineer

    Security Engineer

    Bilt • Grapevine, TX, United States
    Full-time
    BILT - Global Brand Support Center, Grapevine, Texas 76051.BILT Incorporated is a fast-growing software-as-a-service company revolutionizing instructions and training for consumers and professional...Show more
    Last updated: 30+ days ago • Promoted
    CT Tech PRN

    CT Tech PRN

    Methodist Health System • Midlothian, TX, United States
    Full-time
    PRN (United States of America).In this highly technical allied imaging professional position, you'll collaborate with a multidisciplinary team to provide the very best imaging services, which inclu...Show more
    Last updated: 26 days ago • Promoted
    Lead Application Security Engineer

    Lead Application Security Engineer

    Saxon Global • Irving, TX, United States
    Full-time
    Minimum of 5+ years of experience in Information Security or a related role encompassing security compliance, penetration testing, vulnerability management, and / or static code analysis.Prior experi...Show more
    Last updated: 4 days ago • Promoted
    Security Engineer I

    Security Engineer I

    Kubota • Grapevine, TX, United States
    Full-time
    Applicants must live within the Dallas / Ft.Applicants must be authorized to work for any employer in the U.We are unable to sponsor or take over sponsorship of an employment Visa at this time.BASIC ...Show more
    Last updated: 6 days ago • Promoted
    Manhattan Active Architect - 46686

    Manhattan Active Architect - 46686

    Cognizant • Maypearl, TX, US
    Full-time
    Manhattan Active Warehouse Management Systems (MAWM) Architect.This role will influence strategic IT decisions and ensure seamless integration with supply chain systems. Assess client business requi...Show more
    Last updated: 10 days ago • Promoted
    USA_Senior Security Engineer

    USA_Senior Security Engineer

    Varite • Farmers Branch, TX, United States
    Full-time
    Role Description : Not Available.Competencies : Problem Solving, Identity and Access Management Implementation, Design & Architecture, Operational Risk Management. Strong expertise in IAM Concepts RBA...Show more
    Last updated: 15 days ago • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    Apex Informatics • Irving, TX, United States
    Temporary
    Cyber Security Engineer with Checkmarx(Mandatory).Locations : AZ, CA, MN, NC, NY, NJ & TX (Hybrid), (3 days onsite / 2 WFH). Provide hands on technical support for Checkmarx and Checkmarx ONE platform....Show more
    Last updated: 15 days ago • Promoted
    Application Security Engineer

    Application Security Engineer

    KellyMitchell Group • Irving, TX, United States
    Full-time
    Our client is seeking a Application Security Engineer to join their team! This position is located in Charlotte, North Carolina. Assist with Jenkins builds, onboard teams and troubleshoot issues.Set...Show more
    Last updated: 26 days ago • Promoted
    Sr Security Engineer, Detection Engineering

    Sr Security Engineer, Detection Engineering

    Lennar • Irving, TX, United States
    Full-time
    Sr Security Engineer, Detection Engineering.Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communit...Show more
    Last updated: 17 days ago • Promoted
    Lead Security Engineer - Purple Team (Dallas Ft Worth Metro)

    Lead Security Engineer - Purple Team (Dallas Ft Worth Metro)

    Gartner • Irving, TX, United States
    Full-time
    Hiring near our Irving, TX Center of Excellence with a flexible environment.Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients.W...Show more
    Last updated: 30+ days ago • Promoted
    Lead IT Security Endpoint Engineer (CrowdStrike)

    Lead IT Security Endpoint Engineer (CrowdStrike)

    Dtcc • Coppell, TX, United States
    Full-time
    Are you ready to make an impact at DTCC?.Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC...Show more
    Last updated: 30+ days ago • Promoted
    Cyber Security Engineer I

    Cyber Security Engineer I

    TAMKO • Coppell, TX, United States
    Full-time
    The Cybersecurity Engineer I is a hands-on role that provides critical support to TAMKO's integrated IT and Operational Technology (OT) security operations. This position offers direct exposure to m...Show more
    Last updated: 6 days ago • Promoted
    Application Security Engineer

    Application Security Engineer

    Publicis Groupe Holdings B.V • Irving, TX, United States
    Full-time
    You will help to ensure the secure delivery of Epsilon's software applications by crafting and implementing secure coding practices, conducting advanced security testing through application securit...Show more
    Last updated: 26 days ago • Promoted
    Threat Modelling Engineer

    Threat Modelling Engineer

    ApTask • Irving, TX, United States
    Full-time
    The client is a digital business transformation company that helps organizations thrive in the modern digital economy.It combines strategy, consulting, customer experience, and engineering to drive...Show more
    Last updated: 18 days ago • Promoted
    Lead Application Security Engineer / Veracode / CheckMarx

    Lead Application Security Engineer / Veracode / CheckMarx

    ShiftCode Analytics • Irving, TX, United States
    Full-time
    We need A Senior (10+ years) Lead Application security engineer with excellent experience working with Varacode and CheckMarx along with other security tools. Leader with hands-on engineer with cros...Show more
    Last updated: 4 days ago • Promoted