Назад
Company hidden
13 дней назад

Senior Threat Detection Engineer (Cybersecurity)

152 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Threat Detection Engineer (ICS Cybersecurity): Creating and validating high-fidelity threat detections and asset identification analytics for industrial control system environments with an accent on cyber threat intelligence, packet analysis, and Windows telemetry. Focus on analyzing ICS artifacts and multi-gigabyte datasets, tuning analytics, identifying protocol coverage gaps, and mentoring detection engineers.

Location: United States; remote role

Salary: $152,000 per year, plus competitive equity and comprehensive benefits.

Company

hirify.global provides cybersecurity technology, threat intelligence, and expert services for protecting industrial control systems and other critical infrastructure.

What you will do

  • Create atomic, component, composite, and event-based threat detections and asset identification analytics for ICS environments.
  • Test, validate, tune, and quality-check detections developed by internal teams, trusted advisors, and industry partners.
  • Analyze packet captures, Windows host logs, ICS equipment artifacts, embedded devices, firewalls, network devices, and ICS software.
  • Review and respond to detection support requests, enriching tickets with PCAPs, tags, documentation, and analysis.
  • Document analytics authoring, validation, and testing processes while maintaining the knowledge base on issues and false positives.
  • Partner with Engineering, OT Watch, and Quality Engineering to address protocol coverage gaps and detection issues, and mentor detection engineers.

Requirements

  • 8+ years in security operations, threat hunting, detection development, offensive operations, threat emulation, or security tool development.
  • 2+ years operationalizing cyber threat intelligence to defend networks against emerging threats.
  • 1+ year of direct experience with SCADA, DCS, building automation, or other industrial control system environments.
  • Advanced network packet analysis and manipulation using tools such as Wireshark, Tshark, ngrep, tcpdump, Zeek, or Scapy.
  • Working knowledge of Windows Event Logging, operating system internals, network communications, and large host and network datasets.
  • Ability to mentor detection engineers and communicate effectively through technical writing and presentations.

Nice to have

  • Experience with Suricata, Snort, YARA, Zeek, Splunk, Elasticsearch, or the ECS schema.
  • Programming experience with Python, Rust, Ruby, Go, or Lua.
  • ICS network assessment or penetration testing experience, plus Windows/Linux administration, networking, firewall, or virtualization experience.
  • Cybersecurity certifications such as GICSP, GRID, GCTI, GCIA, GCIH, GCDA, OSCP, OSEP, OSED, CySA+, or PenTest+.
  • Ability to travel less than 10% for team activities, conferences, and customer-site data collection.

Culture & Benefits

  • Remote-first, mission-driven work focused on protecting critical infrastructure.
  • Collaboration with cybersecurity practitioners across North America, Europe, the Middle East, and APAC.
  • Competitive equity package and comprehensive benefits plan.
  • Work environment built around authenticity, transparency, trust, knowledge sharing, and continuous learning.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →