Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

US Threat Led Defense Detection (USTLD) Engineer - USDS

AT TikTok
TikTok

US Threat Led Defense Detection (USTLD) Engineer - USDS

Washington, DC

Responsibilities

About the Team
This role reports to the Threat Led Defense (USTLD) team lead. USTLD's mission is to ensure that the Threat Detection and Response organization can detect and mitigate the most critical threats to our user data, employees, and operations. As a detection engineer, you will onboard, write, and tune detection logic for a variety of network, endpoint, and cloud security use cases.

You would be a great fit if:
- You are a self-starter who is comfortable operating in a fast-paced environment
- You'd like to work with a variety of cross-functional teams on a diverse set of use cases
- You are looking for a high-impact individual contributor role within a growing team
- You enjoy tackling complex or novel challenges.

Want more jobs like this?

Get jobs in Washington, DC delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


In order to enhance collaboration and cross-functional partnerships, among other things, at this time, our organization follows a hybrid work schedule that requires employees to work in the office 3 days a week, or as directed by their manager/department. We regularly review our hybrid work model, and the specific requirements may change at any time.

Tasks and Responsibilities:
- Work with intelligence and engineering teams to assess threat actor tradecraft and develop appropriate countermeasures
- Onboard and tune out-of-the-box detection logic from commercial and internally developed products
- Analyze threat actor TTPs using MITRE ATT&CK and assess detection coverage using MITRE DeTT&CT
- Develop custom rules to address gaps in detection coverage
- Work with logging teams to onboard new log sources to our SIEM
- Contribute to threat hunt operations and purple team exercises
- Build and maintain a threat detection library
- Develop enrichment pipelines and automation to enhance the fidelity of threat detections

Qualifications

Minimum Qualifications
- Bachelor's degree or industry-equivalent work experience in Computer Science, Information Security, Computer Engineering, or a related discipline along with 5+ years experience working in security operations, threat detection, incident response, or related domains
- 2+ years experience with Splunk: ingesting data, writing advanced queries, and building dashboards; proficiency in Splunk SPL
- Proficiency in one or more of the following: Python, PowerShell, YAML, JavaScript
- Comfortable learning and working with internally-developed tools while possessing knowledge of SQL or Lucine syntax with In-depth knowledge of security logging for Linux and macOS
- Experience writing and tuning detection logic for network, host, and cloud use cases
- Understanding of application gateways, firewalls, and network proxies
- Strong written and verbal communication, Excellent analytical and problem-solving skills with attention to detail, Excellent time management and prioritization, Experience mapping threat actor TTPs to the MITRE ATT&CK framework

Preferred Qualifications
- Experience building detections for Linux systems using auditd, osquery, etc.
- Experience updating, maintaining, and creating IDS variables within a complex enterprise network
- Experience assessing detection coverage using MITRE DeTT&CT and Familiarity working with detections-as-code (including git, peer reviews, linting, and CI/CD)
- Experience working with XSOAR (or an equivalent SOAR product) along with Experience using attack simulation frameworks to develop or validate detections
- Relevant certifications are welcomed: OSCP, OSEP, GREM, CISSP, GSEC, CISA, Security+, Network+, etc.

Client-provided location(s): Washington, DC, USA
Job ID: TikTok-7494070652694251794
Employment Type: Other

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • HSA
    • Life Insurance
    • Fitness Subsidies
    • Short-Term Disability
    • Long-Term Disability
    • On-Site Gym
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Snacks
    • Pet-friendly Office
    • Happy Hours
    • Some Meals Provided
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K) With Company Matching
    • Performance Bonus
    • Company Equity
  • Professional Development

    • Promote From Within
    • Access to Online Courses
    • Leadership Training Program
    • Associate or Rotational Training Program
    • Mentor Program
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program
    • Employee Resource Groups (ERG)

Company Videos

Hear directly from employees about what it is like to work at TikTok.