Senior Detection Engineer and Threat Hunter

Autodesk Autodesk · Enterprise · Bangalore, India

Autodesk is seeking an experienced Detection Engineer & Threat Hunter to mature and support structured hunting and detection engineering initiatives. The role involves executing threat hunting and detection engineering engagements, analyzing security event artifacts, and collaborating with Incident Response and Trust stakeholders. Responsibilities include performing threat hunts, building/testing/deploying detections using software engineering practices, researching threat behaviors, recommending improvements, supporting purple team engagements, and deploying/maintaining supportive infrastructure like server-less functions and cloud compute instances using DevOps best practices. Requires 5+ years of experience in threat hunting, threat intelligence, incident response, security engineering (SIEM/SOAR), or detection engineering, with strong proficiency in logging, threat data engineering, and analysis, and hands-on experience with various log/data sources (AWS, Azure, GCP, AD, DNS, etc.). Proficiency in Python, Go, or PowerShell is also required.

What you'd actually do

  1. Perform tailored driven threat hunts, analysis, and detection engineering in support of priority intelligence requirements to identify advanced threats
  2. Build, test, and deploy detections, automations, and alerts using modern software engineering practices (e.g. automated testing/validation and Detections-as-Code)
  3. Research, document, and develop threat detections based on behavioral attributes of actors, malware operators, and general threats to Autodesk interests
  4. Prescribe expert recommendations on ways to improve detection, response, and enterprise defense capabilities
  5. Support our purple team and attack simulation engagements across Security and Product teams

Skills

Required

  • Python
  • Go
  • PowerShell
  • AWS
  • Azure
  • GCP
  • AD
  • DNS
  • proxy
  • firewall
  • EDR
  • webserver
  • SaaS applications
  • SIEM
  • SOAR
  • threat hunting
  • threat intelligence
  • incident response
  • security engineering
  • detection engineering
  • logging
  • threat data engineering
  • analysis
  • cloud compute resources

Nice to have

  • regional languages
  • GCIA
  • GCIH
  • GREM
  • GCTI
  • GCTD
  • GCDA
  • GSEC
  • GCED
  • GDAT
  • computer science
  • information security

What the JD emphasized

  • structured hunting operations centered on adversary lifecycle analysis
  • logging, threat data engineering and analysis
  • analyzing diverse tooling and log/data sources
  • 5+ years of experience working in a threat hunting, threat intelligence, incident response, security engineering (e.g. SIEM or SOAR), or detection engineering role
  • detection engineering and/or threat hunting focused on implementing, sustaining, and enhancing structured hunt operations