Detection Engineer
Rooted · Reston, VA · 5 days ago
EngineeringFull-time
About the role
You translate known attacker techniques into detection rules that work against real production data. The difficulty is not writing a rule that fires on a test case; it is writing one that still identifies the technique months later while producing few enough false positives that the on-call team can trust it. You also run threat hunts to find activity that current detections would have missed.
Responsibilities
- Build detections from real attacker behaviour
- Measure each rule's false positive rate and own it
- Hunt for what current detections would have missed
Requirements
- Knows what attacks look like in telemetry, not just in theory
- Query languages and a scripting language
- Willing to delete your own rules when they stop earning their place
Nice to have
- Purple team experience
- Sigma rules
- Incident response background