Talent.com
Lead Threat Detection Engineer
Lead Threat Detection EngineerMcKesson Corporation • Irving, TX, US
Lead Threat Detection Engineer

Lead Threat Detection Engineer

McKesson Corporation • Irving, TX, US
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you.

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection capabilities and tools. This team is responsible for building detection content, enabling integration, automation, enrichment, and performance of alerts. This role enables speed, quality, and coverage of threats for security operations and reduces risk to McKesson business operations.

Position Description / Responsibilities

  • Mature from a manual detection practice to a modern, automated, and standardized Detection-as-Code practice and infrastructure.
  • Develop use-cases based on intelligence, red team results, and incident data
  • Develop IOC workflows and a feedback loop for the Threat Intel Platform (TIP)
  • Write detection and correlation rules to identify threats across our stack
  • Assist in onboarding logs and identifying gaps in logs or alert results
  • Develop a deep understanding of data models, macros, indexes, sources, and field alias and the technology foundation our detection stack is built
  • Understand data schema / API standards, automation, and messaging systems
  • Bring a metrics-driven mindset to our rules, signals (IOCs), and alerts

Critical Requirements

  • Prioritize detection use-case and scope and create a logical rule
  • Ability to prioritize decisions to either write a rule and / or tune a tool / policy
  • Practical experience with threat Actor tracking, tactics, tools, and techniques and working closely with Intel, SOC, and Red Teams (Purple Teams)
  • Ability to measure detection coverage across common frameworks (e.g. NIST CSF, MITRE, KC) and simplify rules and configurations to optimize alerts
  • Ability to automate tasks via scripting, automating inputs and outputs of APIs, and programming skills such as python to enable detection engineering tasks
  • Exceptional interpersonal, organizational, and communication skills and ability to internalize and exemplify Mckesson core values.
  • Splunk SPL knowledge and SIEM experience or additional SIEM background
  • Following Qualifications would be advantageous :

  • 10+ years of professional experience in two or more domains, including : detection engineering, data engineering, incident response, threat hunting, threat intelligence.
  • Bachelor's degree in computer science, Information Security, Security Engineering, Statistics, or Data Science
  • Chronicle Experience, Splunk Certifications (1,2), Automation certifications (Security with Python SEC573), Sigma Rules
  • We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets.

    The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations.

    In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, pleaseclick here.

    Our Base Pay Range for this position

    $139,000 - $231,600

    McKesson is an Equal Opportunity Employer

    McKesson provides equal employment opportunities to applicants and employees and is committed to a diverse and inclusive environment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age or genetic information. For additional information on McKesson's full Equal Employment Opportunity policies, visit our

    Equal Employment Opportunity

    page.

    Join us at McKesson!

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Detection Engineer • Irving, TX, US

    Job_description.internal_linking.related_jobs
    Senior Product Security Engineer - Applications

    Senior Product Security Engineer - Applications

    Altice USA • Plano, TX, United States
    serp_jobs.job_card.full_time
    Are you looking to Optimize your life? Start your exciting path to a rewarding career today!.We are Optimum, a leader in the fast-paced world of connectivity, and we're on the hunt for enthusiastic...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    M516- (764117)Cybersecurity Engineer

    M516- (764117)Cybersecurity Engineer

    FHR • Dallas, TX, US
    serp_jobs.job_card.full_time
    Our client has an opening for a Cybersecurity Engineer 3 (764117).This position is up to 5 months with the option of extension. The client is located in Richmond, VA.IT security or cloud security ro...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    MTA - Sr. Application Security Engineer

    MTA - Sr. Application Security Engineer

    MCKESSON • Irving, TX, United States
    serp_jobs.job_card.full_time
    McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.We are known for delivering insights, products, and services that make quality care more accessibl...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Endpoint Security Lead (Associate Director) - CrowdStrike

    Endpoint Security Lead (Associate Director) - CrowdStrike

    Glocomms • Dallas, TX, United States
    serp_jobs.job_card.full_time
    A top-tier financial services firm is seeking a seasoned cybersecurity professional to lead the design, deployment, and governance of enterprise endpoint protection solutions.This leadership role i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Cyber Security Engineer

    Cyber Security Engineer

    APCON • Plano, TX, US
    serp_jobs.job_card.full_time
    We are seeking a highly motivated.You will play a critical role in supporting the development, testing, and guidance of our proprietary security application—designed, built, and deployed enti...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Systems Field Engineer

    Security Systems Field Engineer

    Digi Security Systems • Dallas, TX, US
    serp_jobs.job_card.full_time
    We've built our reputation on innovation and reliable service, and we're known as the industry's experts.Field Engineer to join our operations in the. This person will be responsible for...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Endpoint Security Lead (Associate Director) - CrowdStrike (Dallas)

    Endpoint Security Lead (Associate Director) - CrowdStrike (Dallas)

    Glocomms • Dallas, TX, US
    serp_jobs.job_card.part_time
    A top-tier financial services firm is seeking a seasoned cybersecurity professional to lead the design, deployment, and governance of enterprise endpoint protection solutions.This leadership role i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Principal Network Security Cyber Defense Consultant

    Principal Network Security Cyber Defense Consultant

    Verizon • Irving, TX, United States
    serp_jobs.job_card.full_time +1
    A place to share your ideas freely - even if they're daring or different.Where the true you can learn, grow, and thrive.At Verizon, we power and empower how people live, work and play by connecting...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Sr. Security Engineer

    Sr. Security Engineer

    Varo Bank • Dallas, TX, US
    serp_jobs.job_card.full_time
    Varo is an entirely new kind of bank.All digital, mission-driven, FDIC insured and designed for the way our customers live their lives. We are looking for an experienced Senior Security Engineer res...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Senior Network Security Engineer

    Senior Network Security Engineer

    Fisher Investments • Plano, Texas, United States
    serp_jobs.job_card.full_time
    This job is with Fisher Investments, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.The O...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Strategic Threat Advisor

    Strategic Threat Advisor

    Apollo Information Systems • Dallas, TX, US
    serp_jobs.job_card.full_time
    Job Title : Strategic Threat Advisor.OUR PURPOSE IS TO CREATE A SAFE WORLD.Apollo is a multi-national leader in threat intelligence enabled and business risk focused cyber defense.We are changing th...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Enterprise Security Engineer

    Senior Enterprise Security Engineer

    Flexport • Dallas, TX, US
    serp_jobs.job_card.full_time
    At Flexport, we believe global trade can move the human race forward.That's why it's our mission to make global commerce so easy there will be more of it. We're shaping the future of a $...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Engineer (Dallas)

    Security Engineer (Dallas)

    Insight Global • Dallas, TX, US
    serp_jobs.job_card.full_time +1
    Job Title : Remote Security Engineer.We are seeking a hands-on Security Engineer to serve as the internal subject matter expert (SME) supporting a large managed security services partnership with HC...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    GoodLeap • Plano, TX, US
    serp_jobs.job_card.full_time
    GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, w...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Manager, Detection Engineering and Security Automation

    Manager, Detection Engineering and Security Automation

    Gartner • Irving, TX, United States
    serp_jobs.job_card.full_time
    Hiring near our Irving, TX Center of Excellence with a flexible environment.Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients.W...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    Secur-Serv • Fort Worth, TX, US
    serp_jobs.job_card.full_time
    Secur-Serv is a leading managed services provider of IT, print, and hardware services, with a security focus at the core of every service. Secur-Serv provides nationwide, on-site service to business...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Lead Product Security Engineer

    Lead Product Security Engineer

    Dematic Corp. (ILD-US) • Plano, TX, United States
    serp_jobs.job_card.full_time
    We are looking for a hands-on and highly motivated Lead Product Security Engineer to join our Product Security Operations team. In this role, you'll help protect and scale our cloud environment and ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Security Engineer - Detection & Response

    Security Engineer - Detection & Response

    Nerdy • Dallas, TX, US
    serp_jobs.job_card.full_time
    You are an AI-powered Security Engineer responsible for identifying and responding to malicious or suspicious activity across our environment with speed and confidence. This role leads the engineeri...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Lead Security Engineer - Purple Team (Dallas Ft Worth Metro)

    Lead Security Engineer - Purple Team (Dallas Ft Worth Metro)

    Gartner • Irving, TX, United States
    serp_jobs.job_card.full_time
    Hiring near our Irving, TX Center of Excellence with a flexible environment.Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients.W...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    Insight Global • Dallas, TX, United States
    serp_jobs.job_card.full_time
    Job Title : Remote Security Engineer.We are seeking a hands-on Security Engineer to serve as the internal subject matter expert (SME) supporting a large managed security services partnership with HC...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted