Назад
Company hidden
13 часов Π½Π°Π·Π°Π΄

Security Detection Engineer (Cybersecurity)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
remote (Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Poland)/onsite
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
middle
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
Poland
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Security Detection Engineer (Cybersecurity): Developing and productionizing code-like detections for malicious network activity using telemetry such as NetFlow, DNS queries, TLS certificate data, and SMB filenames with an accent on behavioral modeling, threat intelligence, and network security. Focus on tuning detection efficacy with precision, recall, false-positive rate, and MITRE ATT&CK coverage while deploying detections to SaaS and potential on-premise environments.

Location: Poland; remote or office work options available

Company

hirify.global delivers engineering and technology services, including cybersecurity and SaaS solutions.

What you will do

  • Design behavioral models and production-ready detections for malicious network activity and anomalies.
  • Develop detection logic for beaconing, DGA, data staging, lateral movement, DNS tunneling, scanning, port hopping, and unusual remote administration.
  • Build, evaluate, and continuously tune detections using precision, recall, false-positive rate, and MITRE ATT&CK coverage.
  • Use production-scale telemetry in Databricks to validate detection performance.
  • Collaborate with threat intelligence and engineering teams to turn threat research into detection content and productionize it in SaaS and potential on-premise environments.
  • Support threat hunting, investigations, triage, and documentation of detection methodology and tuning decisions.

Requirements

  • Experience developing rule-based, signature-based, or behavioral detection content for network threats.
  • Strong knowledge of TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectors.
  • Proficiency in Python and SQL for detection development and data analysis.
  • Experience with Sigma, Snort, Suricata, or similar detection formats.
  • Practical experience applying AI/ML techniques to security detection, including anomaly detection, classification, or behavioral modeling.
  • Experience with SecOps workflows, threat intelligence tools, NDR, security analytics or SIEM solutions, and MITRE ATT&CK mapping.

Nice to have

  • Endpoint security experience.

Culture & Benefits

  • Remote or office work format in Poland.
  • Collaboration with threat intelligence teams, including Cisco Talos.
  • Cross-team knowledge sharing across security and engineering functions.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’