Aspenview Technology Partners logo
Hiring from
Colombia
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.

As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

Here’s what you can expect:

  • Competitive base
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together

The Senior Detection Engineer is a hands-on professional responsible for designing, building, testing and tuning the detections that decide which security events become alerts for a 24/7 SOC serving a large US consumer lender. Working on-site from AspenView's secure delivery suites in Bogotá or Buenos Aires, you will work across telemetry from CrowdStrike, Microsoft Defender, Okta, Palo Alto, Proofpoint and AWS flowing through Abstract Security into Elastic. You will be one of two senior detection engineers on the service, reporting to a US-based Detection Engineering Lead you speak with daily. This role calls for real autonomy: you will be expected to take a use case from idea to production without being walked through it.

What you will do:

Detection Development

  • Own detection use cases end to end, from threat research and logic to testing against simulated attacks, documentation and release, with client approval for changes that affect alerting.
  • Build correlation and multi-stage detections across endpoint, identity, network, email and cloud telemetry, designed around the attack chains a consumer lender actually sees.
  • Create custom IOAs in CrowdStrike, custom detections in Microsoft Defender, identity detections on Okta, and AWS control-plane coverage.

Tuning & Data Quality

  • Tune the noisiest and weakest rules with evidence, documenting what changed, the effect on the false-positive rate, and proof the rule still catches what it should.
  • Fix parsers and data-quality issues when a source routed through Abstract arrives in Elastic incomplete or mis-mapped.

Collaboration & Continuous Improvement

  • Peer review rules with your fellow detection engineer and turn hunt findings and Tier 2 feedback into backlog items.
  • Work alongside the threat hunters on the same floor, turning good hunts into production detections.
  • Support major incidents when needed by writing emergency detections or sweeping for related activity.

Tools & Technologies:

  • SIEM & Detection: Elastic Security (EQL, ES|QL, KQL); Splunk (SPL), Sentinel or Chronicle also relevant.
  • Data Pipeline: Abstract Security, or equivalents such as Cribl or Logstash.
  • Endpoint, Identity & Cloud: CrowdStrike Falcon, Microsoft Defender, Okta System Log, AWS CloudTrail and GuardDuty.
  • Engineering: Git, Python or PowerShell, and MITRE ATT&CK.
  • Testing & Automation (Bonus): Sigma, YARA, Atomic Red Team, Caldera and SOAR playbooks.

What you bring:

  • Experience: Several years writing, testing and tuning detections in production on a SIEM or analytics platform, with rules you can explain and defend. Deep query skills in at least one detection language and the ability to pick up another quickly.
  • Technical Depth: Understanding of how attacks show up across endpoint, identity and cloud telemetry, mapped to MITRE ATT&CK, plus working knowledge of log pipelines and where data goes missing between source and alert.
  • Communication: English at B2 or above, strong enough to defend a rule's logic to a US-based lead and the client's security team.
  • Mindset: Autonomous and evidence-driven. You treat detections as code, with Git, peer review and testing before release, and you follow security rules and change control consistently.
  • Availability: On-site work in Bogotá or Buenos Aires during US Eastern business hours, with no shift rotation. Access requires identity, criminal background, employment and education checks, repeated periodically.
  • Bonus Qualifications: Hands-on Elastic Security (the most valuable extra on this stack); Abstract Security, Cribl or Logstash; CrowdStrike custom IOAs and Defender advanced hunting; financial services experience under SOX or PCI DSS; a background in incident response or threat hunting; and GCDA, GCIA, GCED, SC-200 or Elastic certifications.

Visa Sponsorship

AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.

Equal Opportunity Employer

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

Similar jobs

Apply for this job