Senior Detection Engineer; EDR, Autonomous Defense
Listed on 2026-10-09
-
IT/Tech
Cybersecurity, AI Engineer (Applied/Software)
- We’re hiring a Senior Detection Engineer to be the blue team voice inside the Defensive Agent team
- You’ll sit between Product and Engineering as the person who defines what “correct” means
- When an attack technique is detected, you decide what remediation that claim requires
- Your judgment becomes the ground truth
- This is not a coding role and it is not a product management role
- Product owns the roadmap, Engineering owns the implementation, and our AI researchers own how the agents reason
- You own the domain truth all three depend on, and you make it concrete enough to build and measure against
- If you’ve spent your career being the person in the room who knows how the tools really behave, this is a seat where that knowledge teaches a system instead of firefighting alerts
- Partner with Product to turn EDR effectiveness and tuning ambitions into concrete, buildable requirements
- Translate blue team workflows and pain into prioritized product outcomes, and push back when a proposed feature or agent behavior would not hold up in a real SOC
- Define acceptance criteria for detection, effectiveness, and tuning features, and validate releases against them before customers see them
- Serve as the standing domain reference for Engineering and AI research: available for design reviews, technique questions, and vendor behavior questions
- Own deep, current knowledge of the major EDR and endpoint platforms at the console, policy, telemetry, and API level
- Maintain fluency in how detection logic, prevention policy, exclusions, and tuning actually work in each product, including the differences between default and hardened configurations
- Define the vendor-specific policy semantics, so a recommended change means the same thing across platforms that model it differently
- Track platform changes, new detection capabilities, and vendor guidance, and keep our coverage model current as vendors ship
- Define what a correct tuning recommendation looks like and grade agent output against that standard
- Partner with the Attack team so technique coverage and detection expectations stay grounded in current adversary tradecraft
- Growth Opportunities:
Be part of a dynamic and growing team with numerous career advancement opportunities - Innovation-Driven Culture:
Work in a collaborative environment that encourages creativity and out-of-the-box thinking - Flexible Work Environment:
Enjoy the convenience and work-life balance that comes with remote work - Inclusive and Diverse Team:
We value diversity and promote an inclusive culture where everyone can thrive
6+ years in detection engineering, security operations, incident response, or threat hunting, with meaningful time spent as a practitioner rather than an advisor
Solid understanding of post-compromise attacker behavior and how each surfaces in endpoint and identity telemetry
Hands-on operational experience administering and tuning EDR platforms in production — writing detections, managing policy and exclusions, and investigating real alerts
Fluency in false positive and false negative tradeoffs, alert fatigue, and detection coverage measurement
Strong working knowledge of MITRE ATT&CK and detection coverage frameworks, and a clear view of where they help and where they mislead
Deep understanding of what a SOC actually does with EDR output
Ability to influence without authority. You will not manage the engineers or own the roadmap, and you will still be expected to move both Enough scripting ability, ideally Python, to query APIs, inspect telemetry, and prototype an analysis
Demonstrated experience shaping a product or platform as a domain expert, whether in a security vendor, an internal tooling team, or a detection engineering function
Comfort with SQL and with reasoning over large volumes of event and telemetry data Comfort translating between audiences: engineers, AI researchers, product managers, SOC analysts, and executives
Exceptional technical writing. Most of your leverage here comes from written artifacts — requirements, methodology docs, labeling guides, tuning content
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).