

EP181 Detection Engineering Deep Dive: From Career Paths to Scaling SOC Teams
23 snips Jul 15, 2024
Zack Allen, Senior Director at Datadog, discusses challenges in detection engineering and advice for aspiring engineers. Topics include the role of detection engineers, balancing vendor-made vs. custom detections, and tips for building effective detection rules. The podcast explores the importance of connecting detection efforts with business objectives and provides recommended reading materials to enhance detection engineering skills.
AI Snips
Chapters
Transcript
Episode notes
Detection Engineering Challenges
- Detection engineering has three core components: software/DevOps, threat expertise, and statistics.
- Scaling these three skills simultaneously is crucial for success in the field.
Cost of Consumption
- Consuming detections without engineering shifts the cost, not eliminates it.
- Someone handles the resulting false positives, feedback loops, and data source management.
Getting into Detection Engineering
- Aspiring detection engineers need coding comfort, threat detection expertise (cloud, host, network, email), and ideally, a focus area.
- Start with a simple project like securing a Minecraft server on a cloud platform.