07 oct
|
AspenView Technology Partners
|
Bogotá
07 oct
AspenView Technology Partners
Bogotá
Why Join AspenView?
At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.
Here’s what you can expect:
- Competitive base
- Versátil work model: hybrid, remote, or in-office
- Real growth opportunities and leadership visibility
- Inclusive, respectful culture that blends U.S. innovation with Colombian heart
- A company that listens, invests in you, and celebrates wins together
The Senior Detection Engineer is a hands-on professional responsible for designing, building, testing and tuning the detections that decide which security events become alerts for a 24/7 SOC serving a large US consumer lender. Working on-site from AspenView's secure delivery suites in Bogotá or Buenos Aires, you will work across telemetry from CrowdStrike, Microsoft Defender, Okta, Palo Alto, Proofpoint and AWS flowing through Abstract Security into Elastic. You will be one of two senior detection engineers on the service, reporting to a US-based Detection Engineering Lead you speak with daily. This role calls for real autonomy: you will be expected to take a use case from idea to production without being walked through it.
What you will do
Detection Development
- Own detection use cases end to end, from threat research and logic to testing against simulated attacks, documentation and release, with client approval for changes that affect alerting.
- Build correlation and multi-stage detections across endpoint,
identity, network, email and cloud telemetry, designed around the attack chains a consumer lender actually sees.
- Create custom IOAs in CrowdStrike, custom detections in Microsoft Defender, identity detections on Okta, and AWS control-plane coverage.
Tuning & Data Quality
- Tune the noisiest and weakest rules with evidence, documenting what changed, the effect on the false-positive rate, and proof the rule still catches what it should.
- Fix parsers and data-quality issues when a source routed through Abstract arrives in Elastic incomplete or mis-mapped.
Collaboration & Continuous Improvement
- Peer review rules with your fellow detection engineer and turn hunt findings and Tier 2 feedback into backlog items.
- Work alongside the threat hunters on the same floor, turning good hunts into production detections.
- Support major incidents when needed by writing emergency detections or sweeping for related activity.
Tools & Technologies:
- SIEM & Detection: Elastic Security (EQL, ES|QL, KQL); Splunk (SPL), Sentinel or Chronicle also relevant.
- Data Pipeline: Abstract Security, or equivalents such as Cribl or Logstash.
- Endpoint, Identity & Cloud: CrowdStrike Falcon, Microsoft Defender, Okta System Log,
AWS CloudTrail and GuardDuty.
- Engineering: Git, Python or PowerShell, and MITRE ATT&CK.;
- Testing & Automation (Bonus): Sigma, YARA, Atomic Red Team, Caldera and SOAR playbooks.
What you bring:
- Experience: Several years writing, testing and tuning detections in production on a SIEM or analytics platform, with rules you can explain and defend. Deep query skills in at least one detection language and the ability to pick up another quickly.
- Technical Depth: Understanding of how attacks show up across endpoint, identity and cloud telemetry, mapped to MITRE ATT&CK;, plus working knowledge of log pipelines and where data goes missing between source and alert.
- Communication: English at B2 or above, strong enough to defend a rule's logic to a US-based lead and the client's security team.
- Mindset: Autonomous and evidence-driven. You treat detections as code, with Git, peer review and testing before release, and you follow security rules and change control consistently.
- Availability: On-site work in Bogotá or Buenos Aires during US Eastern business hours, with no shift rotation. Access requires identity, criminal background, employment and education checks, repeated periodically.
- Bonus Qualifications: Hands-on Elastic Security (the most valuable extra on this stack); Abstract Security, Cribl or Logstash; CrowdStrike custom IOAs and Defender advanced hunting; financial services experience under SOX or PCI DSS; a background in incident response or threat hunting; and GCDA, GCIA, GCED, SC-200 or Elastic certifications.
📌 Detection Engineering (Bogotá)
🏢 AspenView Technology Partners
📍 Bogotá