Job Description
A client with Kforce is seeking an IR/Digital Forensics to join their team in Charlotte, NC.
Duties:
- Design, build, and tune detection rules and correlation logic across Splunk, CrowdStrike NG-SIEM (LogScale/CQL), Zscaler, and Onyx Security, with an emphasis on reducing false-positive rate and closing coverage gaps
- Build and maintain API- and Lambda-based orchestration pipelines that route alerts from detection platforms into ServiceNow Security Incident Response (SIR), enriching alerts with context before they reach a responder
- Partner with Detection Platform Engineering to align new detections with existing data models, ingestion pipelines, and the broader detection roadmap
- Work directly with Incident Responders (DFIR, Insider Risk) to understand investigative gaps and translate them into new or refined detection logic
- Support playbook development: partnering with responders to codify triage steps, escalation criteria, and containment actions into ServiceNow SIR workflows and SOAR-style automation
- Validate detections against live test data and known TTPs; Document tuning decisions and false-positive rationale for audit and hand-off
- Participate in post-incident lessons-learned reviews, converting findings into detection or playbook updates
- Maintain detection-as-code practices: version control, peer review, and change documentation for all production detection logic
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent hands-on experience (4+ years in lieu of degree is common in this field and reasonable to accept)
- Relevant certifications a plus, not required: GCIA, GCDA, CrowdStrike CCFA/CCFR, Splunk Certified Power User/Admin, or AWS Security certifications
- 4-7 years of total security engineering/detection engineering experience, with at least 2 years with touching multi-platform detection work (not single-tool)
- Hands-on detection engineering experience in Splunk (SPL) and CrowdStrike NG-SIEM/LogScale (CQL), including correlation searches, bucket (groupBy) logic, and multi-source joins
- Practical experience with API-based integrations and AWS Lambda for security automation/orchestration (alert routing, enrichment, or automated response)
- Experience with ServiceNow Security Incident Response (SIR): case creation via API, field mapping, and workflow logic
- Working knowledge of Zscaler logging and how to build detections off proxy/DNS/SSL telemetry
- Familiarity with MITRE ATT&CK and translating adversary behavior into detection logic
- Strong cross-functional communication: able to work shoulder-to-shoulder with IR analysts and platform engineers, not just ship detections over the wall
- Scripting proficiency (Python preferred) for automation and API work
Preferred:
- SOAR platform experience (Splunk SOAR, Palo Alto XSOAR, Tines, or similar)
- Experience building or supporting IR playbooks/runbooks in a live SOC
- Cloud security monitoring experience (AWS/Azure/GCP logging)
- Exposure to AI agent security/governance platforms (e.g., Onyx Security) or willingness to ramp quickly on tool
- Familiarity with UEBA or insider-risk detection concepts
Job Tags
Contract work