
Detection Engineer, Protective Services
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
β’ Develop technical capabilities to identify and analyze threats to safeguarded individuals.
β’ Create detections, enrichment, and automation across identity, endpoint, cloud, marketplace, support, physical access, and open-source signals.
β’ Convert threat intelligence, incidents, investigative requirements, and observed behaviors into actionable detections.
β’ Test, implement, optimize, and maintain detections and associated pipelines at scale.
β’ Correlate enterprise telemetry, marketplace activities, physical security events, OSINT, support interactions, and other relevant data.
β’ Utilize rules, statistical methods, machine learning, and LLM-based techniques to enhance detection quality and investigative context.
β’ Investigate detections by querying and correlating data, validating hypotheses, and evaluating confidence, scope, and impact.
β’ Continuously enhance detection logic, tools, and workflows based on investigation results and false-positive assessments.
β’ Contribute to technical reviews, testing, documentation, standards, and automation efforts.
β’ Engage in on-call duties and support significant investigations.
β’ Collaborate with Protective Services, engineering, investigative, and response teams.
β’ Report directly to the Engineering Manager, Protective Services.
β’ Over 3 years of experience in detection engineering, threat hunting, incident response, security operations engineering, technical threat intelligence, or software engineering applied to security challenges.
β’ Proven experience in contributing to production detection pipelines utilizing source control, testing, review, deployment, and monitoring practices.
β’ Proficiency in SQL or a security query language.
β’ Capability to write maintainable code in Python, Go, or another relevant programming language.
β’ Strong analytical abilities to explore unfamiliar datasets, assess data quality, troubleshoot across systems, and formulate testable detection hypotheses.
β’ Experience in triaging alerts and investigations, correlating signals across various data sources, and communicating evidence-supported conclusions.
β’ Familiarity with building detections or conducting investigations using security, behavioral, or other relevant telemetry.
β’ Experience leveraging automation or analytics to enhance detection and investigation workflows.
β’ Knowledge of MITRE ATT&CK or D3FEND frameworks.
β’ Excellent collaboration and communication skills.
β’ Ability to manage sensitive information responsibly.
β’ Bachelor's degree or equivalent practical experience.
β’ Familiarity with Snowflake, Cortex, or Google SecOps is preferred.
β’ Equity grants.
β’ 401(k) plan with employer matching.
β’ 16 weeks of paid parental leave.
β’ Wellness benefits.
β’ Commuter benefits match.
β’ Paid time off.
β’ Paid sick leave.
β’ Medical, dental, and vision benefits.
β’ 11 paid holidays.
β’ Disability insurance.
β’ Basic life insurance.
β’ Family-forming assistance.
β’ Mental health program.
β’ Flexible paid time off/vacation for salaried positions.
β’ 80 hours of paid sick time per year for salaried roles.
β’ Premium healthcare.
β’ Wellness expense reimbursement.
Green Energy Venture AG
Abacus Group
EXP
Get handpicked remote jobs straight to your inbox weekly.