11 дней назад
Senior Threat Research Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Threat Research Engineer (Cybersecurity): Building scalable security detections for identity threats, malicious activity, and emerging attack patterns across cloud and SaaS environments with an accent on threat modeling, detection logic, telemetry, and production engineering. Focus on measuring detection precision and recall, investigating false positives and negatives, and developing a unified detection program across Taiwan, the US, the UK, and Australia.
Location: Taipei, Taiwan
Company
Security provides a SaaS security platform that helps organizations reduce risk, detect and respond to threats, and prevent breaches across business applications such as Microsoft 365 and Salesforce.
What you will do
- Establish the detection engineering function in Taiwan, including technical direction, operating standards, and hiring plans.
- Research cloud, identity, and SaaS threats and translate attacker behavior into threat models and actionable detection opportunities.
- Design, author, test, maintain, and release detection rules and behavioral detection models.
- Define telemetry, enrichment, correlation, and historical context requirements while partnering with platform and data engineering on scalable production pipelines.
- Build frameworks for detection testing, simulation, coverage measurement, versioning, release management, and ongoing tuning.
- Investigate false positives and false negatives, improve detection quality, and collaborate with Security Research, Product Management, Engineering, and Customer Success.
Requirements
- Significant experience in detection engineering, threat research, security analytics, incident response, threat hunting, or a related security discipline.
- Experience leading security research or detection initiatives and mentoring practitioners.
- Strong knowledge of attacker behavior, identity threats, cloud security, and enterprise SaaS environments.
- Experience developing production detections with rules, queries, correlations, statistical methods, or behavioral models.
- Experience analyzing large security datasets, including audit events, authentication activity, identity data, application logs, or cloud telemetry.
- Strong written and verbal communication skills in English and the ability to collaborate across regions, time zones, functions, and cultures.
Nice to have
- Experience with identity security, SaaS security, cloud detection and response, SIEM, UEBA, EDR, or XDR products.
- Familiarity with identity-based attacks, MITRE ATT&CK, detection-as-code, rule languages, detection engines, or automated validation frameworks.
- Experience applying machine learning, anomaly detection, or generative AI to security problems.
- Experience investigating real-world intrusions, working with incident response teams, or building detection engineering teams.
- Experience working in Taiwan or with globally distributed APAC teams; Mandarin proficiency.
Culture & Benefits
- Collaborate with teams across Taiwan, the US, the UK, and Australia to build a unified global detection program.
- Work on a SaaS security platform protecting more than 200 organizations across multiple regions.
- Contribute to a disciplined detection lifecycle covering research, development, validation, deployment, monitoring, tuning, and retirement.
- Focus on explainable, actionable security findings and measurable customer impact.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →