T-Mobile US - Frisco, TX
posted 3 months ago
The Detection Engineering Sr. Engineer at T-Mobile plays a crucial role in enhancing the company's security detection capabilities. This position is responsible for identifying suspicious and malicious activities swiftly and accurately, thereby protecting both T-Mobile's customers and employees. The engineer will collaborate with various teams within security operations to ensure comprehensive protection across all platforms, including T-Mobile.com, corporate networks, and individual user endpoints. The role involves working with multiple technologies and data sets to build robust security detection frameworks, utilizing tools such as SIEM, EDR, and network monitoring systems. In this position, the engineer will be instrumental in designing and building a comprehensive threat detection program. They will work closely with partners across security and engineering to develop and refine threat detection logic, enhance response capabilities, and deploy new tools. The engineer will also be responsible for identifying active threats to T-Mobile's system environments, informing log ingestion requirements for threat detection use case development, and researching new attack techniques to improve detection logic. This includes creating custom logic, detection rules, and alerts to identify suspicious patterns and activities, as well as managing the security detection lifecycle by maintaining, tuning, and deprecating detection rules as necessary. Additionally, the engineer will develop content to improve detection capabilities in security tooling and work with incident response teams to address security incidents promptly. They will champion process improvements, recommend tools or infrastructure changes, and lead small to medium-sized projects, taking ownership of solutions from inception to completion. The role also involves developing and delivering metrics to measure the effectiveness of detection efforts and participating in the Cyber Incident Response Team rotation, which may require non-traditional working hours.