Remote job
Detection Engineer (Threat Research)
Job details
About this role
Role overview Build and maintain security detections by translating threat research into rules that identify adversary behavior while limiting false alarms. The remote, full-time position combines report analysis, detection engineering, technique mapping, peer review, and validation against emulated activity on Windows and Linux systems.
Responsibilities - Develop and maintain detection rules and decoders for adversary techniques on Windows and Linux. - Read threat reports to identify observable behavior, relevant log sources, and useful fields. - Map detection content to MITRE ATT&CK techniques and sub-techniques, documenting supporting evidence. - Contribute research on relevant threat groups and the techniques they use. - Review teammate and AI-assisted detections for false positives, overly broad logic, and mapping errors. - Validate rules against emulated activity and record potential evasion gaps.
Requirements - 1–3 years of experience in a SOC, detection, threat hunting, or threat intelligence role. - Working knowledge of Linux and Windows security logs. - Ability to write scripts in Python or a shell language such as Bash. - Familiarity with Git and GitHub, virtualization, and Linux containers. - Knowledge of CVEs, SOC/SIEM operations, or security hardening. - Careful, evidence-based approach to reviewing detection logic and AI-assisted output.
Nice to have - Public security contributions such as Sigma rules, technical blog posts, or CTF write-ups.
Benefits and work setup - Fully remote, full-time work. - Competitive salary, home office budget, and opportunities for professional growth.