Назад
Company hidden
2 дня назад

Sr. Detection Engineer (Cybersecurity)

130 900 - 169 400$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Detection Engineer (Cybersecurity): Writing and validating production detection logic across endpoint, identity, cloud, SaaS, network, and application telemetry with an accent on adversary emulation, telemetry analysis, and detection quality. Focus on building repeatable attack-testing tooling, sandbox infrastructure, automated regression testing, and AI-assisted workflows for exploit and malware analysis.

Location: Chicago, Illinois, United States; Flex/Hybrid

Salary: $130,900–$169,400 base salary annually, plus potential incentive compensation and long-term equity participation.

Company

hirify.global provides financial market infrastructure, trading, clearing, and investment solutions for market participants worldwide.

What you will do

  • Write, tune, and maintain production detection logic across SIEM, EDR, identity, and cloud platforms.
  • Validate detections by executing the techniques they target and confirming both attack coverage and benign-activity behavior.
  • Build adversary-simulation tooling, reusable validation packages, automated regression tests, and coverage reporting.
  • Build and operate sandbox and detonation infrastructure for exploit triage, malware analysis, and safe technique development.
  • Evaluate exploit proof-of-concept code, analyze generated telemetry, and convert findings into detection and threat-hunting content.
  • Support incident response and application/API security testing while translating findings into detection and remediation guidance.

Requirements

  • 5+ years of hands-on security engineering experience with substantial detection-authoring experience.
  • Strong command of at least one detection query language, such as KQL, Sigma, or YARA-L.
  • Practical knowledge of attacker techniques across Windows, Active Directory, Entra ID, AWS, Azure, SaaS, and containerized workloads.
  • Ability to analyze unfamiliar exploit or malware code and identify reliable observable artifacts.
  • Experience with a tooling language such as Python, Go, C#, PowerShell, or Bash, plus virtualization, containers, infrastructure-as-code, and CI/CD.
  • Must be legally authorized to work in the United States without current or future employer sponsorship; visa sponsorship is not available. Bachelor’s degree or equivalent practical experience is required.

Nice to have

  • Public detection content, tooling, or security research.
  • Atomic testing frameworks, continuous control validation, or MITRE ATT&CK coverage analysis.
  • AI engineering, agentic workflows, MCP integration, or LLM-application abuse testing.
  • Reverse engineering, Windows internals, EDR telemetry, or evasion research.
  • Financial-services or regulated-enterprise experience, mentoring, or internal training experience.

Culture & Benefits

  • Flexible hybrid work environment.
  • Health, dental, vision, telemedicine, and mental health benefits.
  • Paid vacation, personal, sick, and community-service days.
  • 401(k) match of up to 8% immediately upon hire, plus employee stock purchase options.
  • Tuition assistance, parental leave, fertility benefits, fitness facilities, and charitable giving support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →