高级检测分析师
Senior Detection Analyst
Zscaler (NASDAQ: ZS) 加速数字化转型,使客户能够更加敏捷、高效、有韧性且安全。Zscaler Zero Trust Exchange™ 平台通过在任何位置安全连接用户、设备和应用程序,保护数千家客户免受网络攻击和数据丢失。该基于 SASE 的 Zero Trust Exchange 分布在全球 160 多个公共交换点以及边缘的数千个私有交换点,是全球最大的在线云安全平台。
我们相信未来的工作是“人类 + AI”,正在打造一个以 AI 为核心的企业,通过机器智能放大人类潜能,解决世界上最困难的安全挑战。我们以深入的客户需求为导向,致力于使命、成果以及彼此之间。我们通过三种核心行为将这些承诺付诸实践:以结果和影响建立信任,拥有责任感和协作精神,以及具有持续反馈的挑战文化。准备好在引领 AI 时代安全变革的公司中产生影响吗?加入我们,成为 Zscaler 的一员。
职位
我们正在寻找一名高级检测分析师加入我们的团队。这是一个远程职位(位于哥斯达黎加),向检测分析经理汇报,属于检测运营团队。你将利用我们的检测平台分析多个检测领域(包括终端、身份、网络和云)中的遥测数据、警报和日志源,为我们的托管检测与响应客户提供威胁报告。此外,通过领导改进检测运营工作流程的项目,实现编排和自动化,确保我们的客户能够获得高精准度的威胁分析,并以简洁明了的方式传达有关新兴威胁的信息。
你将负责(职位期望)
- 在多个检测领域(包括终端、身份、网络和云/SaaS)中分析 EDR 遥测数据、警报和日志源
- 使用简洁明了的沟通方式为客户发布和审查威胁,有效传达关键指标和修复上下文
- 通过编排和自动化改进并创新检测运营工作流程,以处理大量遥测数据
你是什么样的人(成功画像)
- 你像主人翁一样行动,对我们的使命充满热情,以诚信行事,并能在高层次战略和实际操作之间无缝切换
- 你是一个高度值得信赖的合作者,通过清晰、尊重的反馈拥抱挑战文化,以构建强大的团队
查看英文原文
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform.
We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler.
Role
We are looking for a Senior Detection Analyst to join our team. This is a remote role (in Costa Rica), reporting to the Manager, Detection Analyst in the Detection Operations Team. You will utilize our detection platform to analyze telemetry, alerts, and log sources across several detection domains including Endpoint, Identity, Network, and Cloud to publish threats for our Managed Detection and Response customers. Additionally, by leading projects to improve the Detection Operations workflow through orchestration and automation, you will ensure our customers receive high-fidelity threat analysis and concisely written communication regarding emerging threats at scale.
What You’ll Do (Role Expectations)
- Analyze EDR telemetry, alerts, and log sources across several detection domains including Endpoint, Identity, Network, and Cloud/SaaS
- Publish and review threats for customers using concisely written communication to effectively convey key indicators and remediation context
- Improve and innovate Detection Operations workflows through orchestration and automation to manage high volumes of telemetry
Who You Are (Success Profile)
- You act like an owner with a passion for our mission, operating with integrity and navigating seamlessly between high-level strategy and hands-on execution.
- You are a high-trust collaborator who embraces a challenge culture through clear, respectful feedback to build trust and elevate the team.
- You are customer-obsessed, anchoring decisions in solving real-world problems and championing customer needs from start to finish.
- You are data-driven, using analytics to measure what matters, replace assumptions with evidence, and guide informed decisions.
- You think at scale, connecting daily work to the global mission while building resilient solutions designed to last in a high-growth organization.
What We’re Looking for (Minimum Qualifications)
- Demonstrated curiosity and active exploration of AI tools, with a proven history of integrating new technologies to enhance daily workflows and augment problem-solving
- Strong experience in Endpoint (EDR) and one or more functional areas including Cloud/SaaS, Identity, Email, or Network detection domains
- Experience with DevOps workflows and common scripting languages such as Python, Ruby, and PowerShell
- Expertise using query languages and understanding syntax across EDR or other security platforms such as SQL or Lucene
- Awareness of the current attack landscape (current threats, attack techniques, and vulnerabilities)
- Strong analytical, documentation, and communication skills
What Will Make You Stand Out (Preferred Qualifications)
- Previous professional experience in a Red Team or offensive security capacity
- Active involvement in the Infosec community through writing blogs, participating in webinars, or presenting at conferences
- Familiarity with MITRE ATT&CK TTPs
#LI-KM9 #LI-Remote
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
- Various health plans
- Time off plans for vacation and sick time
- Parental leave options
- Retirement options
- Education reimbursement
- In-office perks, and more!
Learn more about Zscaler's hybrid working model and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.