Security Engineer, Detection & Response
TL;DR Kharon is seeking a full-time, remote-based Security Engineer, Detection & Response to join our Information Security team.
RESPONSIBILITIES:
- Lead the architecture, implementation, and configuration of our centralized SIEM solution.
- Design and maintain robust log ingestion pipelines from key sources as Cloud Service Providers (AWS, GCP), Endpoint Protection, Identity and Access Management, Device Management etc.
- Develop, test, and deploy custom detection rules to identify malicious activity. Map our detection coverage against the MITRE ATT&CK framework.
- Triage security events and lead security incident response efforts. Build automation scripts (Python/SOAR) to enrich alerts and reduce manual toil.
- Relentlessly tune alerts to minimize false positives, ensuring the team focuses on genuine threats (combating alert fatigue).
- Partner with DevOps and IT to ensure critical systems are generating the right telemetry and that security blind spots are illuminated. Generate automated reporting assisting with evidence collection for compliance and investigations.
QUALIFICATIONS:
- 5+ years in Information Security with a focus on Detection & Response, SOC Engineering, or Blue Teaming.
- Must possess an expert-level Linux background (Ubuntu, RHEL, Amazon Linux etc.)
- Proven experience setting up a SIEM from scratch or significantly refactoring an existing deployment (e.g., Splunk, Panther, Elastic, Datadog Security, Sumo Logic).
- Expertise in SIEM-specific languages (e.g., KQL, SPL, SQL, ES|QL, OPAL).
- Deep understanding of AWS security (CloudTrail, GuardDuty, VPC Flow Logs, s3, IAM) and how to detect threats in a cloud-native environment.
- Expertise in multi-stage data parsing (Regex, Grok, KQL Parse) to transform raw, unstructured logs into actionable security intelligence.
- Familiarity with telemetry from EDR tools (CrowdStrike) and Identity Providers (Okta/Google).
- Proficiency in Python or Bash for automating log analysis and response tasks.
- Familiarity with common compliance frameworks such as SOC, ISO, GDPR etc.
- You are comfortable working with ambiguity and enjoy creating processes where none existed before.
- Bonus points if you have the following experience:
- Infrastructure as Code (Terraform) to deploy security logging infrastructure.
- Ethical Hacking/Penetration Testing background
- Experience with Tailscale or Zero Trust networking concepts.
- Knowledge of Osquery for endpoint visibility.
Kharon is a highly disruptive and incredibly innovative organization that navigates risk at the intersection of global security threats + international commerce.
What does that mean? Great question.
Operating at the nexus of global security, Kharon is on a mission to revolutionize the current landscape. We take really complex data as it relates to global security and empower our clients to not only understand the risk associated with their potential business relationships but to operationalize that data so that they can make the best and most informed decisions possible. From financial crimes and sanctions to export controls and threat identifications, our tools optimize protection against the types of risks that could otherwise be incredibly dangerous and excessively costly to any business. Serving many of today’s leading global financial and multinational institutions, Kharon products are the most powerful in the space with a precision and depth that is absolutely unparalleled.
When you look at any major global crisis event, we’re providing intelligence that’s at the heart of those circumstances. We connect the dots in a way that’s meaningful. Now, we’re experiencing unprecedented growth. As the world continues to evolve in complexity, so too does the demand for our products. Given the significance of our work and the increasing global reliance on our insights, we are looking for a Director of Growth Marketing to join us as we work to shape the way businesses perceive and navigate global risks.
Reporting to the VP of Info Security, we are looking for a hands-on Security Engineer to build the foundation of our Detection and Response capabilities. In this role, you will be taking the lead on building out the security detection and response playbooks which includes our logging and monitoring across the entire environment. You will own the deployment and configuration of our SIEM, establish critical data pipelines from our core infrastructure (AWS, Okta, CrowdStrike, etc.), and turn raw logs to render high-fidelity signals. You will act as the primary subject-matter expert for incident investigation and work closely with our engineering teams to harden our platform.
To the right person, this will be the perfect kind of challenge. Our mission is compelling, our product is powerful, and we’re growing at a rate that makes us unstoppable. If you’re looking to be surrounded by people who will inspire you to think and challenge you to grow then look no further. Our team is made up of some of the most visionary and uncompromising individuals you will ever encounter. We don’t take ourselves seriously but we’re serious about the work we do and there is absolutely no slowing us down.
To keep that momentum going, we do our very best to make sure that each and every team member is completely taken care of. We’re nothing without our people and we strive to offer a package that reflects that. As a Kharon team member, you can expect:
- Fully sponsored medical, dental, and vision
- FSA program for both medical and dependent care
- 401k + Roth with matching and immediate vesting
- Paid time off + 11 paid holidays
The base salary range at Kharon is set between $160,000-$180,000. Please note that this figure does not necessarily include potential bonuses, commissions, benefits, or equity that may be part of the overall compensation package.
If interested in pursuing this position, please visit www.kharon.com to apply.
Kharon is committed to cultivating and maintaining a workplace that is free from harassment and discrimination. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ethnicity, gender, gender identity or expression, sexual orientation or identity, neurodiversity, appearances, age, protected veteran status, or status as a qualified individual with disability.