Senior Cloud Detection Engineer

Bank of America Bank of America · Banking · Denver, CO +2

This role focuses on designing, building, and tuning AWS security detections using Splunk within a Cyber Security Operations team. It involves reducing false positives, increasing detection coverage, translating threat scenarios into actionable detections, and providing escalation support for AWS-related alerts. The role also aims to build a detection engineering lifecycle for SIEM platforms covering on-prem and multi-cloud environments.

What you'd actually do

  1. Design, build, and tune AWS security detections using Splunk
  2. Reduce false positives and improve alert fidelity
  3. Partner with cloud and security teams to increase detection coverage
  4. Translate threat scenarios into actionable detections
  5. Act as L2 escalation support for complex AWS-related alerts

Skills

Required

  • Cyber Security experience
  • Cloud SOC experience
  • Purple Team roles experience
  • Writing and tuning detections
  • SIEM tools including Splunk
  • Designing and implementing technical solutions to enhance visibility, alerting capabilities, and reduce risk within AWS
  • Reviewing applications, infrastructure, and architectural designs to identify threats and vulnerabilities
  • AWS native services and tools
  • Threat frameworks, such as MITRE ATT&CK for Cloud and D3FEND
  • Risk Management principles
  • Building, configuring, operating and/or securing cloud infrastructure and applications in AWS
  • Assessing risks and identifying vulnerabilities in infrastructure
  • Partnering with incident response teams, threat intelligence researchers, Red/Purple teams, and/or HUNT researchers
  • Common Information Security and data protection frameworks and standards (i.e. CIS, NIST, HIPAA, GDPR, PCI DSSS, ISO 270001)
  • Navigating and collaborating effectively within a geographically complex and dispersed global corporation
  • Excellent verbal and written communication skills

Nice to have

  • CCSP / CCSK
  • CISSP / CISM / Security +
  • Bachelor’s or Master’s Degree in Computer Science, Information Systems, Cyber Security, or related field
  • DevOps Practices
  • Test Engineering

What the JD emphasized

  • AWS native services and tools (i.e. Guard Duty, CloudTrail, Security Hub)
  • MITRE ATT&CK for Cloud
  • HIPAA
  • GDPR
  • PCI DSSS
  • ISO 270001