Назад
Company hidden
11 часов назад

Detection Engineering Lead (AI)

200 000 - 250 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Detection Engineering Lead (AI): Building and improving an AI agent that generates detection content across SIEM, EDR, NDR, cloud, identity, and SaaS security platforms with an accent on adversary tradecraft, detection efficacy, and security operations. Focus on encoding expert detection knowledge into software, evaluating AI-generated detections, and developing autonomous workflows for threat intelligence and threat hunting.

Location: Remote - US; 100% remote from home with semi-frequent local and national travel to professional offices and events.

Salary: $200,000–$250,000 USD per year, plus equity and benefits.

Company

hirify.global is a venture-backed cybersecurity company building generative AI security specialists to augment security engineers and analysts.

What you will do

  • Prototype, validate, and continuously improve an AI agent that programmatically generates detection content across diverse security environments.
  • Encode expert detection engineering knowledge into the product in partnership with engineering and product teams.
  • Design scoring rubrics for AI-generated detection content across SIEM, EDR, NDR, cloud, identity, and SaaS platforms.
  • Establish methodologies and best practices for detection quality, tuning, testing, and lifecycle management.
  • Experiment with autonomous agentic loops connecting detection engineering, threat intelligence, and threat hunting.
  • Research emerging threats, attacker techniques, detection gaps, and AI-assisted approaches to threat detection.

Requirements

  • 5+ years of detection engineering experience.
  • Deep expertise with at least two major SIEM platforms, such as Microsoft Sentinel, Splunk, QRadar, Elastic, Chronicle, or Sumo Logic.
  • Strong understanding of endpoint, cloud, identity, network, and SaaS telemetry.
  • Expertise in MITRE ATT&CK, adversary emulation, detection coverage analysis, and high-fidelity detections at scale.
  • Strong knowledge of attacker tradecraft across Windows, Linux, cloud, identity, and SaaS environments.
  • Excellent communication skills, an early-stage startup mindset, and a data-driven approach.

Nice to have

  • Experience leading detection engineering programs in large, complex environments.
  • Expertise with EDR platforms such as CrowdStrike, Microsoft Defender, SentinelOne, or Palo Alto Cortex XDR.
  • Experience with AWS, Azure, and GCP security platforms.
  • Familiarity with AI, machine learning, LLMs, or autonomous security workflows.
  • Experience with open-source detection content such as Sigma, YARA, Suricata, or Zeek, plus public speaking or research publications.

Culture & Benefits

  • 100% remote work from home with company-provided equipment.
  • Semi-frequent local and national professional travel with some overnight travel.
  • Company-paid health insurance and a 401(k) plan with employer match.
  • Self-managed PTO and parental leave.
  • Significant new-hire equity grants and potential bonuses.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →