Detection Engineer ; Remote
St. Paul, Saint Paul, Ramsey County, Minnesota, 55118, USA
Listed on 2026-06-07
-
IT/Tech
Cybersecurity
Location: St. Paul
Grey Noise Intelligence is a mission driven security startup focused on helping organizations understand and mitigate risks from Internet scanning and exploitation. Grey Noise provides real-time, verifiable intelligence on all actors scanning the Internet and how some of them are attempting to exploit vulnerabilities on assets connected to corporate networks. The intelligence is highly trusted because it’s generated from a global fleet of thousands of purpose built sensors observing the Internet.
Advanced data science techniques and AI are used to process millions of observed events into real-time intelligence for customers.
The Grey Noise Global Observation Grid observes and analyzes unique threat data at-scale that no one else can. Grey Noise provides the most actionable threat intelligence against perimeter threats, so that no attack works twice.
All US based positions are fully remote within the US, with optional office attendance at our DC area headquarters, unless otherwise specified. Applicants must have US work authorization.
Please see the specific job description for all international position locations.
The RoleGrey Noise is hiring a Detection Engineer to own the high-volume, foundational detection work that keeps our datasets accurate and our customers protected. This role is intentionally focused on operational execution: building, validating, and maintaining detections at scale.
Responsibilities Detection and Traffic Tagging Operations- Write and tune Intrusion Detection System rules grounded in observed network behavior.
- Maintain and improve tag coverage and quality: adding new tags, fixing broken ones, and de-duplicating overlaps.
- Maintain benign actor classifications and known-scanner lists so non-malicious traffic is accurately labeled.
- Resolve accumulated detection issues that degrade data quality for users and customers.
- Use internal CLI tooling to lint, test, and deploy detection rules and tags at scale.
- Read and analyze packet captures (pcaps) and related network artifacts during routine validation and debugging.
- Validate detections against real traffic and own the trade-offs between false positives and false negatives for individual rules.
- Triage a steady stream of inbound detection requests, CVEs, and internal coverage questions. The team processes dozens of new items weekly.
- Ensure detections are wired correctly end-to-end: from raw data through rule logic to tag output.
- Flag edge cases, collisions, and unexpected behavior in tags or rules for deeper follow-up.
- Work closely with researchers to keep them focused on longer-horizon projects.
- Communicate clearly about what you are working on, blockers, and trade-offs when priorities shift.
- Help sales, support, and customer success get faster, clearer answers on detection coverage questions.
- The backlog of smaller yet important detection work stops growing and quietly gets handled.
- Tag and detection coverage feels predictable and systematic rather than ad hoc.
- Internal teams get faster, clearer answers on coverage questions.
- The rest of the research team has noticeably more uninterrupted time for complex work and bigger bets.
- You develop reliable instincts for which detection issues matter most and can prioritize without constant direction.
We are flexible on the level. This could be filled by someone in early to mid-career or by a senior practitioner willing to own operational detection work as a primary focus, with a possible path toward deeper research responsibilities over time.
Early-Career or Mid-Level- Comfortable with networking fundamentals and common protocols.
- Can read pcaps today, or is eager to get to "pcaps in your sleep" quickly.
- Understands basic security concepts: CVEs, exploit vs. vulnerability, false positives vs. false negatives.
- Thrives on clear queues of work and shipping lots of small, concrete things.
- Wants broad exposure to real-world internet traffic and detection engineering.
- Strong background in detection engineering, DFIR, SOC operations, or network security.
- Sees operational detection work as the foundation for credible research, not a stepping stone past it. Expect to own this for 6 to 9+ months before the role naturally expands.
- Can turn vague problems into scoped, repeatable workflows.
- Understands that high-leverage impact often comes from unglamorous, highly reliable execution.
- Demonstrated ability to read and analyze packet captures (pcaps).
- Experience writing or maintaining Suricata rules or similar network detection signatures.
- Comfort with high context-switching: moving between tags, rules, pcaps, and internal requests throughout the day.
- Strong attention to detail; small mistakes in tags or rules have outsized downstream effects.
- Clear, concise written communication, especially when something is broken, ambiguous, or blocked.
- Experience with IDS/IPS platforms, Suricata, Zeek, Sigma, Nuclei, or Snort.
- Prior exposure to large-scale…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).