Jobs · Information Technology

Staff Diagnostics and Embedded Cyber Security Engineer

CyberJobs.Com · Sunnyvale, CA · 2 wk ago
Information Technology$129k–$212k/yrFull-time
We need to output HTML fragment with sections: headings

for sections like About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. Only include sections that have real specific content. We must not repeat job title as heading. No Job ID etc. Remove boilerplate. Must preserve all substantive info. We need to parse the posting. Company description: LinkedIn description. Probably not needed? It's part of description but not a section heading? Could be part of "About the company"? Not required heading. We can include as

maybe under a generic "About LinkedIn"? But we only output sections when there is real content. The instruction: "use

for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." So we can include those headings if content exists. Also we can include other headings like "About The Team" maybe as

About the Team? The instruction says use those examples but not limited? It says use

for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). So we can use those headings; we could also use "About The Team" as a heading if appropriate. Probably safe to include headings for sections present: About The Team, About The Role, Responsibilities, Qualifications (Basic and Preferred), Suggested Skills, Benefits (including culture and pay), Pay (explicit), Schedule (Workplace Type). Also maybe "Additional Information" but that's boilerplate EEO etc, we should remove. So we will omit EEO etc. We need to preserve all substantive information: company description, team description, role description, responsibilities list, qualifications (basic and preferred), suggested skills, benefits (culture, health wellness, pay range, bonus, stock, benefits link), pay range, schedule (Hybrid or Remote). Also location details: remote anywhere in US or hybrid in Mountain View office. We must not include duplicated lines. Remove cookie/navigation/legal/EEO etc. We need to format lists with
  • . For prose use

    . We must not include placeholders like "commensurate with experience". Not present. We need to ensure we don't invent. Let's extract content. Company Description paragraph: "LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed. Join us to transform the way the world works." That's substantive; we can include as a

    maybe under a heading "About LinkedIn" or just as intro before sections. Since no heading required, we can just put

    at top. About The Team: paragraph about Information Security organization, Detection Engineering team responsibilities. We'll put under

    About the Team

    then

    ... . About The Role: paragraph about senior individual contributor duties. Under

    About the Role

    ... . Responsibilities: list of bullet points. We'll put

    Responsibilities

      each bullet as
    • . Need to preserve all bullet text exactly. Let's list responsibilities from posting: - Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry; measure precision/recall, latency, lift, and signal-to-noise ratio. - Build detections-as-code with version control, CI/CD, unit/integration tests, staged canary rollouts, and safe rollback. - Author and maintain SIGMA rules; translate SIGMA to KQL/SQL as needed. - Integrate multi-cloud telemetry: Azure (Activity/Diagnostics), AWS (CloudTrail, GuardDuty), GCP (Cloud Audit Logs, SCC). - Operationalize Microsoft Defender XDR and Sentinel signals; leverage Entra ID controls (Conditional Access, sign-in risk). - Proactive threat hunting; create hunt playbooks and convert findings into detections. - Build IR automation (SOAR/Logic Apps) for triage, enrichment, containment, and case workflow; integrate with ticketing/chat ops. - Operationalize threat intelligence: ingest/normalize IOCs/TTPs, enrich detections with TI context, and turn reports into testable hypotheses. - Own telemetry quality for assigned pipelines: schemas/normalization (e.g., ASIM/OCSF-like), enrichment, data contracts, reliability SLIs/SLOs. - Participate in incident retros; add post-incident detections and suppress noisy patterns. - Participate in on-call for critical detection pipelines and high-severity investigations. We need to keep punctuation as is. Qualifications: there are Basic Qualifications and Preferred Qualifications. We can combine under

      Qualifications

      maybe separate subheadings? But instruction says use

      for section headings; we could have

      Basic Qualifications

      and

      Preferred Qualifications

      . That's okay. Basic Qualifications list: - BA/BS Degree in CyberSecurity, Information Security, Computer Science or related technical discipline, or related practical experience. - 3+ years in security, detection engineering or incident response. - Experience building detection content and analytics for SIEM/XDR/EDR and cloud telemetry (Azure/AWS/GCP). - Experience programming for detections/automation (e.g., Python) and query languages (e.g., KQL/SQL/SPL). - Experience with detections-as-code (tests, CI/CD, canary/rollback) at scale. - Experience with attacker TTPs (MITRE ATT&CK) and detection efficacy metrics. - Experience with schemas/data models (e.g., OSSEM/ASIM-like) and telemetry pipelines. Preferred Qualifications list (multiple lines): - BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience. - Operating detections over large-scale, multi-region pipelines. - Detection testing harnesses, synthetic signal, and adversary emulation at scale. - Identity/security signals (Entra ID/Okta/SSO), endpoint internals (Windows/Linux/macOS), SaaS logs. - Applied analytics/ML for anomaly detection or risk scoring with robust evaluation. - Experience building hypotheses and content for AI-enabled attack patterns; practical use of AI to improve detection workflows. - Hands-on SIGMA authoring/translation; experience with adversary emulation/purple-team validation. - Experience with Microsoft Sentinel, Defender XDR, Entra ID; KQL, Python; GitHub Actions/Azure DevOps; Logic Apps; Azure Data Explorer/Kusto - Experience with Azure Activity/Diagnostics; AWS CloudTrail/GuardDuty; GCP Cloud Audit Logs/SCC We need to keep each bullet as
    • . Suggested Skills: list: "Information SecurityDetection EngineeringDetection as codeKQL". Actually the posting: "Suggested Skills Information SecurityDetection EngineeringDetection as codeKQL". Probably missing commas. We'll treat as separate items: Information Security, Detection Engineering, Detection as code, KQL. We'll make
      • each. Benefits: The posting includes: "We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels. LinkedIn is committed to fair and equitable compensation practices. The pay range for this role is $129,000 to $212,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor. The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For more information, visit https://careers.linkedin.com/benefits." We need Benefits section maybe includes health and wellness programs, time away, etc. Pay range is separate maybe under Pay heading. But we could combine Benefits and Pay? The instruction: include a section ONLY when posting has real, specific content for it. So we can have Benefits (health and wellness programs, time away) and Pay (pay range, bonus, stock). Also Schedule (Workplace Type: Hybrid or Remote). We'll separate. Benefits content: "We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels." Also maybe "For more information, visit https://careers.linkedin.com/benefits." That's a link; we can include as

        with . We'll keep. Pay content: The pay range sentence and following sentences about actual compensation, total compensation package may include annual performance bonus, stock, benefits etc. We'll put under

        Pay

        ... . Schedule: "Workplace Type: Hybrid or Remote" plus details: "This role can be remote anywhere in the United States or be hybrid in LinkedIn’s Mountain View office location." Also earlier: "At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. This role may be remote or hybrid. At LinkedIn, hybrid roles are performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team. Remote roles are performed from the designated home work location upon time of hire, and any changes to this home work location requires a review of remote status and approval." We'll include that as prose under Schedule. We must not include boilerplate like Equal Opportunity Statement etc. Now construct HTML. We'll start with company description

        . Then

        About the Team

        ... . Then

        About the Role

        ... . Then

        Responsibilities

          ...
        . Then

        Basic Qualifications

          ...
        . Then

        Preferred Qualifications

          ...
        . Then

        Suggested Skills

          ...
        . Then

        Benefits

        ... maybe include link. Then

        Pay

        ... . Then

        Schedule

        ... . Make sure no extra whitespace issues. Let's craft. Company description paragraph: exactly as given. About The Team paragraph: "LinkedIn’s Information Security organization protects our members, data, and platforms by building resilient security controls, detecting threats early, and partnering across engineering to reduce risk at scale. The Detection Engineering team is responsible for building and scaling LinkedIn’s threat detection capabilities. We partner closely with Incident Response, Threat Intelligence, Red and Purple Teams, Product Security, Identity & Access Management, and Cloud Security to identify, contextualize, and detect adversary activity across the enterprise. Our team develops and maintains high-fidelity detections while advancing the underlying security telemetry ecosystem through log ingestion, schema design, data normalization, automation, threat hunting, incident response support, and audit enablement." About The Role paragraph: "As a senior individual contributor, you will design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments. You will leverage detections-as-code practices, telemetry modeling, and data-driven efficacy measurements to continuously improve detection coverage and quality. Working from adversary TTPs and threat hypotheses, you will develop resilient, low-noise detections validated through purple-team exercises, adversary emulation, and real-world incident learnings. This is a hands-on engineering role focused on

Similar jobs