- Company Name
- Ciena
- Job Title
- Product Security Detection Engineer
- Job Description
-
Job title: Product Security Detection Engineer
Role Summary:
Lead the design, implementation, and operationalization of a detection engineering capability across a product portfolio, integrating logging, telemetry, SIEM, and threat intelligence to enhance product security visibility and compliance.
Expectations:
- 8+ years of experience in security engineering, detection engineering, or product security.
- Proven ability to translate penetration test, PSIRT, and threat intelligence findings into actionable, product‑specific detections and alerts.
Key Responsibilities:
- Define and standardize logging and telemetry for product teams, ensuring SIEM‑readiness.
- Design and implement detection frameworks covering log collection, TTP‑based detections, vulnerability checks, and hardening compliance automation.
- Architect, develop, and maintain custom detection scripts, alert packs, and detection‑as‑code solutions.
- Develop metrics and dashboards (e.g., MTTD, detection precision, coverage) to gauge detection effectiveness.
- Embed detection checkpoints into the product lifecycle in partnership with R&D, PLM, and Compliance teams; ensure alignment with regulations (NIST, ISO, EU CRA, NIS2, etc.).
- Mentor engineers on rule creation, data quality, and event design.
- Present program progress to senior leadership, security councils, and in customer security reviews.
Required Skills:
- Strong knowledge of logging architectures, telemetry design, and SIEM platforms (Splunk, QRadar, Elastic, Sentinel).
- Hands‑on experience with threat detection logic, MITRE ATT&CK mapping, and detection‑as‑code practices.
- Proficiency in Python, JSON, and scripting for automation and data normalization.
- Familiarity with NIST 800‑53, ISO 27001, CIS Benchmarks, and industry regulatory requirements for logging and monitoring.
- Experience with vulnerability management, PSIRT processes, or red/blue team findings.
- Excellent communication skills for cross‑functional collaboration and stakeholder reporting.
Required Education & Certifications:
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or related field.
- Certifications relevant to security (e.g., CISSP, CISM, CompTIA Security+, or equivalent) are an asset.