2 дня назад
Senior Detection Engineering & Threat Hunting Analyst (Cybersecurity)
150 000 - 170 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Detection Engineering & Threat Hunting Analyst (Cybersecurity): Building and maintaining scalable, high-fidelity detections and conducting hypothesis-driven hunts across identity, endpoint, and security telemetry with an accent on threat intelligence, adversary tradecraft, and AI-assisted analysis. Focus on detecting stealthy intrusions across millions of endpoints, tuning false positives and false negatives, and translating IOCs and TTPs into production-ready rules.
Location: Remote US
Salary: $150,000–$170,000 base plus bonus and equity
Company
builds cybersecurity technology backed by a 24/7 human-led Security Operations Center to protect businesses and service providers from cyber threats.
What you will do
- Create, test, monitor, tune, promote, and retire detection rules across ITDR, SIEM, EDR, Windows, Linux, and macOS.
- Conduct hypothesis-driven threat hunts across telemetry from millions of endpoints to identify stealthy attacker techniques.
- Translate threat intelligence, IOCs, TTPs, and investigation findings into detections through Git-based workflows.
- Build hunting dashboards and queries, review ambiguous attacker activity, and escalate likely intrusions for deeper investigation.
- Collaborate with engineering, the SOC, and adjacent teams to maintain a scalable, high-fidelity detection portfolio.
- Contribute findings to community projects and create technical content such as blogs, videos, podcasts, and webinars.
Requirements
- 2+ years of experience in detection engineering, threat hunting, SOC, MDR, or incident response.
- Intermediate knowledge of Windows internals and working knowledge of Linux, macOS, Microsoft 365, Azure, and Google Workspace.
- Experience developing, testing, tuning, and documenting detections or analytics from threat intelligence, hypotheses, or investigations.
- Familiarity with Sigma, Suricata, Snort, YARA, KQL, EQL, ES|QL, or Splunk SPL.
- Understanding of adversary tradecraft, including persistence, privilege escalation, defense impairment, lateral movement, discovery, and collection.
- Ability to validate AI-generated outputs and communicate findings through clear written reports.
Nice to have
- Intermediate knowledge of Linux and macOS internals.
- Experience with OSquery, Velociraptor, or EDR/MDR/XDR platforms.
- Experience with endpoint forensic tools such as EZ Tools, RegRipper, Hayabusa, or Chainsaw.
- Intermediate malware analysis skills.
Culture & Benefits
- 100% remote work environment.
- Paid vacation, sick time, holidays, and 12 weeks of paid parental leave.
- Medical, dental, vision, life, and disability insurance plans.
- 401(k) with a 5% contribution regardless of employee contribution.
- Stock options for all full-time employees.
- Home office reimbursement, monthly digital reimbursement, education assistance, and access to BetterUp coaching.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Senior SOC Analyst (Cybersecurity)
108 000 - 135 000CAD
Robinhood
3 дня назад
Senior Security Engineer, Detection & Response
146 000 - 220 000$
2 дня назад
Threat Analyst 1 (Cybersecurity)
56 000 - 93 000CAD
8 дней назад
EDR Engineer / Senior EDR Engineer (Cybersecurity)
78 500 - 117 500$
2 дня назад
Application Security / DevSecOps Engineer (AI)
120 000 - 150 000$
4 дня назад