Sporty Group
Mission
Strengthen Sporty’s detection and response capability by tuning EDR, SIEM, and security monitoring platforms so they produce high-quality alerts, reduce noise, and give security teams clear signals on real threats.
The Purple Operations Engineer owns the quality, coverage, and reliability of security detections across endpoint, identity, cloud, network, and application telemetry. This role works closely with Threat Intelligence, Red Team, Purple Team, SOC, Detection Engineering, and Incident Response to convert threats, incidents, and attack simulations into tuned alerts, correlation rules, dashboards, playbooks, and control checks.
What you’ll be doing
- Tune EDR, SIEM, and XDR detections to reduce false positives and improve alert quality.
- Build and maintain detection rules, correlation searches, dashboards, watchlists, and response workflows.
- Translate Red Team, Purple Team, incident, and Threat Intelligence findings into repeatable defensive checks.
- Validate that EDR policies, prevention rules, logging, sensor health, and response actions work as expected.
- Review noisy alerts and tune thresholds, exclusions, lookups, entity context, and suppression logic.
- Support SOC analysts with clear alert descriptions, triage steps, severity logic, and escalation guidance.
- Improve log coverage, parsing, field normalization, enrichment, and data quality.
- Map detections to MITRE ATT&CK where useful. ATT&CK is widely used to describe adversary tactics and techniques based on real-world observations.
- Write portable detection content using formats such as Sigma, which is designed as a generic signature format for SIEM detections.
- Track detection gaps, false positive trends, alert health, and platform performance
What you’ll bring
- Experience tuning EDR, SIEM, XDR, or SOC monitoring platforms.
- Strong understanding of endpoint, identity, cloud, network, and web attack behaviors.
- Practical experience writing detection logic in KQL, SPL, EQL, Lucene, Sigma, YARA, or similar.
- Familiarity with MITRE ATT&CK mapping and detection coverage analysis.
- Ability to turn Red Team, Purple Team, and incident findings into clear detection logic.
- Experience reducing false positives through rule tuning, exceptions, automation, and better entity context. Microsoft Sentinel supports this through automation rules and analytics rule changes.
- Strong scripting ability in Python, PowerShell, Bash, or similar.
- Good understanding of SOC workflows, incident triage, escalation, and response playbooks.
- Strong documentation skills.
Technology Expertise
Any of the following: Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Microsoft Sentinel, Splunk Enterprise Security, Elastic Security, Google SecOps, Sigma, YARA, KQL, SPL, EQL, Lucene, Python, PowerShell, Bash, MITRE ATT&CK, Atomic Red Team, Caldera, Vectr, TheHive, Jira, Confluence, GitHub, GitLab, osquery, Sysmon, Zeek, Suricata, AWS CloudTrail, GuardDuty, Azure, Entra ID, Google Workspace, Okta, Cloudflare, Kubernetes logs.
What’s in it for you
- Sporty is a remote first company in pursuit of sustainability
- A competitive salary + individual performance based bonuses every quarter
- 28 days paid annual leave
- Our core working hours are 10am-3pm in your local time zone with flexibility outside of this
- Referral bonuses & flash bonuses
- Top of the line equipment
- Annual company retreats to provide great internal networking opportunities
Interview Process
- Remote video screening with our Talent Acquisition Team
- Online assessment via Hackerrank
- Remote video interview with Team Members (60 Mins)
- Final discussion with the hiring manager (60 mins)
If you’re interested, we encourage you to apply! Every application is reviewed by a member of our team (AI is not used in our recruitment process), and we aim to respond within 48 hours.
Originally posted on Himalayas
To apply for this job please visit himalayas.app.
Working in Afghanistan, Albania, Algeria, Andorra, Angola, Antarctica, Armenia, Austria, Azerbaijan, Bahrain, Belarus, Belgium, Benin, Bosnia and Herzegovina, Botswana, Bouvet Island, Bulgaria, Burkina Faso, Burundi, Cabo Verde, Cameroon, Central African Republic, Chad, Comoros, Congo, Congo, The Democratic Republic of the, Cook Islands, Croatia, Curaçao, Cyprus, Czechia, Côte d'Ivoire, Denmark, Djibouti, Egypt, Equatorial Guinea, Eritrea, Estonia, Eswatini, Ethiopia, Faroe Islands, Finland, France, French Guiana, French Southern Territories, Gabon, Gambia, Georgia, Germany, Ghana, Gibraltar, Greece, Greenland, Guadeloupe, Guernsey, Guinea, Guinea-Bissau, Heard Island and McDonald Islands, Holy See (Vatican City State), Hungary, Iceland, Iran, Iraq, Ireland, Isle of Man, Israel, Italy, Jersey, Jordan, Kazakhstan, Kenya, Kuwait, Kyrgyzstan, Latvia, Lebanon, Lesotho, Liberia, Libya, Liechtenstein, Lithuania, Luxembourg, Madagascar, Malawi, Mali, Malta, Martinique, Mauritania, Mauritius, Mayotte, Moldova, Monaco, Montenegro, Morocco, Mozambique, Namibia, Netherlands, Niger, Nigeria, North Macedonia, Norway, Oman, Palestine, State of, Poland, Portugal, Qatar, Romania, Russian Federation, Rwanda, Réunion, Saint Barthélemy, Saint Helena, Ascension and Tristan da Cunha, Saint Martin (French part), Saint Pierre and Miquelon, San Marino, Sao Tome and Principe, Saudi Arabia, Senegal, Serbia, Seychelles, Sierra Leone, Sint Maarten (Dutch part), Slovakia, Slovenia, Somalia, South Africa, South Sudan, Spain, Sudan, Svalbard and Jan Mayen, Sweden, Switzerland, Syrian Arab Republic, Tajikistan, Tanzania, Togo, Tunisia, Turkey, Turkmenistan, Uganda, Ukraine, United Arab Emirates, United Kingdom, Uzbekistan, Western Sahara, Yemen, Zambia, Zimbabwe, Åland Islands
More jobs at Sporty Group
Keep exploring on Get A Job.ai
Not quite the right fit? Your next opportunity is a click away.
- Browse all jobs
- More jobs by category
- Remote jobs you can do from anywhere
- Research typical pay for this role
- Set a job alert so new matches reach you first
- Upload your resume to apply faster
Hiring instead? Post a job and reach candidates searching right now.