Haystack
← Back to Jobs
Engineering
PI

Content Engineer

Prama Innovations India Pvt. Ltd.Milpitas, CA🇺🇸United StatesPosted 9 Sept 2026

Why This Role Stands Out

This Content Engineer role at Prama Innovations offers a fantastic opportunity to deepen your expertise in cutting-edge security platforms like Microsoft Defender XDR and CrowdStrike, with a contract-to-hire structure providing long-term career potential. You'll thrive if you possess strong skills in EDR policy, automation, and SIEM/detection engineering, enabling you to directly impact the company's security posture. We encourage you to apply and explore this exciting chance to grow your career.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Milpitas, CA, United States
Posted
Yesterday
Jira

Job Description

Location: Milpitas, CA
Work Model: Onsite 4 days/week; flexible when needed
Employment Type: Contract-to-Hire

Non-Negotiable Skills

  • EDR Policy & Configuration
  • Microsoft Defender XDR
  • CrowdStrike Falcon
  • SOAR & Automation

Role Overview

We are seeking a Content Engineer to support the security operations function with a strong focus on hands-on configuration and tuning of security platforms. The role will work across Microsoft Defender, Microsoft 365 security configurations, CrowdStrike, and Sublime Security to align security controls with corporate policies and reduce organizational risk.

The ideal candidate will have strong automation skills to streamline content deployment, reduce manual effort, and maintain consistency across security platforms. The role will also involve reviewing control coverage, identifying gaps, and implementing remediation to strengthen the overall security posture.

Key Responsibilities / Skills

  • SIEM / Detection Engineering
    • KQL, SPL, YARA-L, Sigma
    • Detection logic design, false-positive tuning, detection-as-code
    • MITRE ATT&CK mapping and coverage gap analysis
    • Log source onboarding, parsing, normalization, and field mapping
    • Alert triage pipeline design, enrichment, severity, and suppression
  • EDR Policy & Configuration
    • Microsoft Defender XDR, ASR rules, tamper protection, exclusions, custom detections
    • CrowdStrike Falcon, prevention policies, sensor grouping, IOA rules, Fusion SOAR, RTR
    • EDR exclusion governance and endpoint telemetry tuning
  • DNS Security
    • Infoblox BloxOne
    • Cloudflare Gateway
    • DNS threat analysis including DGA, DNS tunneling, and beaconing
  • Email Security
    • Sublime Security
    • Microsoft Defender for Office 365
    • Proofpoint / Mimecast
    • SPF/DKIM/DMARC and email header analysis
  • SOAR & Automation
    • Microsoft Sentinel Playbooks / Logic Apps
    • VirusTotal, Shodan, WHOIS, and threat-intelligence API integrations
    • ServiceNow / Jira workflow automation
    • Python / PowerShell scripting
  • Threat Intelligence
    • MISP, OpenCTI, Anomali, Recorded Future
    • IOC lifecycle management
    • Intel-to-detection pipelines

Similar jobs