About the role
Join Point72’s Innovative Technology Team
At Point72, we are revolutionizing the investment landscape, and our Technology group plays a crucial role in enhancing our IT infrastructure, keeping us ahead in a fast-evolving tech environment. Our team of experts is continually exploring new avenues, leveraging open-source solutions, and embracing agile methodologies. We foster an environment of professional growth, encouraging you to bring innovative ideas to our projects while satisfying your intellectual curiosity.
Your Role
As a Security Engineer specializing in Detection & Analytics, you will be pivotal in maintaining and advancing Point72's centralized security logging and threat detection systems, addressing essential operational requirements. You will work with large-scale security data, craft sophisticated threat detection and analytical solutions, and significantly influence the firm’s security posture.
- Develop, fine-tune, and maintain customized threat detection rules and alerts in Splunk Enterprise Security, collaborating closely with Security Operations.
- Create and support Splunk dashboards and applications that facilitate threat hunting, risk remediation tracking, and security operations monitoring.
- Integrate detection capabilities with SOAR platforms in collaboration with Security Operations to enhance automation and response workflows.
- Analyze, parse, normalize, and enrich security data to ensure reliable detection, reporting, and analytical outcomes.
- Design and implement automated data ingestion pipelines using agents, syslog, APIs, and database connectors to onboard new log sources.
- Collaborate with Infrastructure, Application, and Security teams to broaden logging coverage and enhance security visibility across both on-premises and cloud environments.
- Operate and optimize the Splunk Enterprise Security platform to ensure stable data ingestion, high availability, and optimal performance.
- Guarantee consistent agent deployment and monitoring coverage across a diverse range of endpoints, servers, and cloud workloads.

