Jobs · Hawaii

Manager, Content Development, Detection Engineering & Automation

KPMG US · Honolulu, HI · 1 wk ago
Hybrid$127k/yrFull-time

Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities.

Responsibilities

  • Execute the end-to-end engineering lifecycle (design, development, testing, deployment, and tuning) for security detection content, utilizing CI/CD pipelines (Detection-as-Code)
  • Collaborate closely with Threat Intelligence, SOC, and Incident Response teams to map detections and automated workflows directly to the MITRE ATT&CK framework
  • Design, write, and optimize high-fidelity detection rules, analytic alerts, and threat-hunting queries using Kusto Query Language (KQL) in Microsoft Sentinel/Azure Data Explorer, while continuously analyzing alert performance and tuning queries to reduce false positives
  • Architect, build, and maintain automated incident response playbooks and custom integrations within Cortex XSOAR, while designing and managing scalable security data pipelines utilizing OpenTelemetry (OTel) to standardize the collection, routing, and processing of logs, metrics, and traces
  • Support and streamline Cyber Operations by actively automating repetitive tasks, threat intelligence enrichment, and other cybersecurity functions to drive down Mean Time to Respond (MTTR)
  • Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment

Qualifications

  • Minimum five years of recent experience in security monitoring, security operations, and incident response, preferably within a professional services or similar environment
  • Bachelor's degree from an accredited college or university is preferred; minimum of a high school diploma or GED is required; the following certifications are preferred - CISSP, CISM, CEH, GIAC, Certified XSOAR Engineer, or other security domain certification
  • Proven hands-on experience administering, configuring, and integrating Security Operations tools (such as Azure Sentinel, XDR, CrowdStrike, XSOAR, ServiceNow, and Splunk) with core IT infrastructure, including proxies, mail servers, Active Directory, workstations, and mobile devices
  • Maintain strong technical knowledge of SIEM, IDS, EDR, DPI, SOAR, OpenTelemetry (OTel), scripting languages, and API usage to support security workflows
  • Serve as the final escalation point to manage and troubleshoot complex detection issues, resolving problems quickly to keep security visibility intact
  • Exhibit strong verbal and written communication skills to interact with individuals at all levels of authority
  • Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future

Benefits

  • Comprehensive medical and dental plans, vision coverage, disability and life insurance
  • 401(k) plans
  • Robust suite of personal well-being benefits to support mental health
  • Personal Time Off per fiscal year, based on job classification, standard work hours, and years of service
  • Two annual breaks where employees will not be required to use Personal Time Off: one at year-end and one around the July 4th holiday

Pay

California Salary Range: $127,200 - $246,900. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications, and market considerations.

Similar jobs