Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Practical Threat Detection Engineering

You're reading from  Practical Threat Detection Engineering

Product type Book
Published in Jul 2023
Publisher Packt
ISBN-13 9781801076715
Pages 328 pages
Edition 1st Edition
Languages
Authors (3):
Megan Roddie Megan Roddie
Profile icon Megan Roddie
Jason Deyalsingh Jason Deyalsingh
Profile icon Jason Deyalsingh
Gary J. Katz Gary J. Katz
Profile icon Gary J. Katz
View More author details

Table of Contents (20) Chapters

Preface 1. Part 1: Introduction to Detection Engineering
2. Chapter 1: Fundamentals of Detection Engineering 3. Chapter 2: The Detection Engineering Life Cycle 4. Chapter 3: Building a Detection Engineering Test Lab 5. Part 2: Detection Creation
6. Chapter 4: Detection Data Sources 7. Chapter 5: Investigating Detection Requirements 8. Chapter 6: Developing Detections Using Indicators of Compromise 9. Chapter 7: Developing Detections Using Behavioral Indicators 10. Chapter 8: Documentation and Detection Pipelines 11. Part 3: Detection Validation
12. Chapter 9: Detection Validation 13. Chapter 10: Leveraging Threat Intelligence 14. Part 4: Metrics and Management
15. Chapter 11: Performance Management 16. Part 5: Detection Engineering as a Career
17. Chapter 12: Career Guidance for Detection Engineers 18. Index 19. Other Books You May Enjoy

Career Guidance for Detection Engineers

As this book comes to a close, if you’re not yet working as a detection engineer, you may be interested in pursuing such a job. This chapter will aim to help answer some questions you may have and provide some guidance to assist in getting your first detection engineering position.

The chapter will cover the following main topics:

  • Getting a job in detection engineering
  • Detection engineering as a job
  • The future of detection engineering
  • Getting involved

The first section is focused on what to look for in job postings, training and certification opportunities, and further ways to develop your detection engineering skills. We’ll then discuss what a day in the life of a detection engineer looks like in terms of job responsibilities. Next, we’ll make some predictions on how detection engineering will evolve over the coming years. Finally, we’ll wrap up with ideas on how you can contribute to...

Getting a job in detection engineering

In this section, we discuss some information on preparing for and finding jobs in detection engineering, starting with what to look for in job postings.

Job postings

The role of a detection engineer is a relatively new one compared to many security and tech positions. As such, there’s not necessarily a standardized job title or description that you’ll find for roles related to detection engineering. For that reason, we must be able to understand the roles and responsibilities of a detection engineer to identify relevant job postings. In the most ideal scenario, the job position will be titled something that clearly indicates it’s a detection engineering role, such as Threat Detection Engineer. In some cases, however, you’ll find detection engineering roles categorized under the broader job title of Security Engineer. This is where an understanding of what a detection engineer does is required. Security engineering...

Detection engineering as a job

In a previous section, we mentioned some examples of responsibilities listed in job postings for detection engineers, which gave a high-level idea of the types of work you’d be performing as a detection engineer. Before we look in more detail at the roles and responsibilities of a detection engineer, we’re first going to discuss some related job roles and how they differ, as well as how those jobs can be used to show your experience in detection engineering when applying for jobs. While there are many sub-specialties in cyber security, we’re going to focus on a few roles that are most closely related to detection engineering in terms of the skills used:

  • Security Operations Center (SOC) analyst
  • Incident responder
  • Threat hunter
  • Threat intelligence analyst/threat researcher

All of these roles, while much different from a full-time engineering position, involve responsibilities that will either directly align...

The future of detection engineering

Detection-as-code is focused on applying engineering and software development processes and technology to detection creation. Therefore, we should continue to see maturity in processes and the adoption of tools and technology most prominently from the software engineering, data engineering, and machine learning fields. There are many external factors that will continue to influence and perpetuate the need for detection engineering. In addition, there are issues that consistently hinder detection creation and some new X-factors that we will need to see if they last through their hype. In the following sections, we have identified many of those areas and how they will affect detection engineering going forward. Writing predictions for the future is a dangerous task, so while we call these predictions, they are mostly trends in the field that we believe will continue the need for detection engineering.

Attack surfaces

The scope of what a company...

Summary

In this final chapter, we moved away from the details of detection engineering processes and pivoted our focus to detection engineering as a career. If you’re reading this book and not already in detection engineering, this chapter was intended to help guide you on your journey to a position in this field. We hope that the information provided here, as well as the skills learned throughout the book help increase your chances of landing such a role. If you’re already in a detection engineering role, hopefully, this chapter and the rest of the book help improve your skills and future in detection engineering.

We hope you enjoyed this book and wish you all the luck on your detection engineering journey!

lock icon The rest of the chapter is locked
You have been reading a chapter from
Practical Threat Detection Engineering
Published in: Jul 2023 Publisher: Packt ISBN-13: 9781801076715
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}