Security Operations Analyst – Detection Engineering & Threat Hunting

TikTok
San Jose
Workplace: OnsiteFull timeFunction: Business OperationsEducation: bachelorsSkills: ["Analytical thinking","Communication","Investigation","Problem-solving"]

Join the IT security team to help strengthen global cyber security operations by monitoring SIEM/IDS/IPS and EDR events, building and tuning high-fidelity detections, and reducing alert fatigue. Conduct threat and scenario-driven threat hunts, identify detection gaps, and operationalize threat intelligence. Design SOAR playbooks, improve detection logic aligned to MITRE ATT&CK and MaGMa, and contribute Python/PowerShell tooling to support a 24/7 SOC workflow.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
TikTok
TikTok
1 month ago

Security Operations Analyst – Detection Engineering & Threat Hunting

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 21 hours agoStatus: Live

Job Summary

Join the IT security team to help strengthen global cyber security operations by monitoring SIEM/IDS/IPS and EDR events, building and tuning high-fidelity detections, and reducing alert fatigue. Conduct threat and scenario-driven threat hunts, identify detection gaps, and operationalize threat intelligence. Design SOAR playbooks, improve detection logic aligned to MITRE ATT&CK and MaGMa, and contribute Python/PowerShell tooling to support a 24/7 SOC workflow.
Location: San Jose
Workplace: Onsite
Employment Type: Full time
Job Function: Business Operations
Seniority: Mid level

Key Responsibilities

  • •Monitor security alerts and events from SIEM, IDS/IPS, firewalls, and EDR systems.
  • •Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry sources.
  • •Conduct threat and scenario-driven threat hunts and close detection gaps found during incidents or hunting.
  • •Design and maintain SOAR playbooks and automation logic for triage, enrichment, and response.
  • •Contribute scripts and tooling (Python, PowerShell) to improve investigation and response efficiency and support 24/7 SOC workflows.

Key Requirements

  • •Bachelor's degree in Computer Science, Cyber Security, or STEM field.
  • •Experience working in or supporting a 24/7 global security operations environment.
  • •Strong proficiency with SIEM platforms (Splunk, Chronicle, Elastic) and EDR tools (SentinelOne, CrowdStrike).
  • •Hands-on experience writing and tuning detection logic (Sigma, EQL, KQL, YARA).
  • •Scripting ability in Python or similar languages to support automation, enrichment, or detection-as-code workflows.
Education:Bachelor's in Computer Science, Cyber Security, or STEM
Skills:Analytical thinkingCommunicationInvestigationProblem-solving
Certifications:GCIHGCIAGCTIOSCP
Tech Stack:SIEMSplunkChronicleElasticIDS/IPSFirewallsEDRSentinelOneCrowdStrikeSigmaEQLKQLYARASOARPythonPowerShellMITRE ATT&CKMaGMaGitOpsCI/CD

Company Brief

TikTok
Short-form video platform that lets users create, share, and discover entertainment content through algorithmic recommendations. It also offers advertising and creator tools for brands, influencers, and businesses.
Industry: Digital Media
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: Singapore, Singapore
Founded: 2016
WebsiteLinkedIn