Senior Detection Engineering & Threat Hunting Analyst
Core
Designing, building, and maintaining scalable detection rules while proactively hunting for stealthy intrusions across millions of endpoints to protect enterprise environments.
Role type
Senior IC detection engineering and threat hunting analyst
Builds
High-fidelity detection portfolio (rules, queries, dashboards) for SOC and partner environments
Domain
Cybersecurity, Threat Intelligence, Endpoint Security
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Detection rule development (Sigma, Suricata, Snort, YARA), Query languages (KQL, EQL, ES|QL, Splunk SPL), Adversary tradecraft knowledge, Threat intelligence analysis, Hypothesis-driven hunting, AI-assisted workflow orchestration, Cross-platform OS knowledge (Windows, Linux, macOS)
Preferred skills
Malware analysis, Forensic tooling (OSquery, Velociraptor, EZ Tools, RegRipper, Hayabusa, Chainsaw), Remote evidence discovery
Technologies
SIEM, EDR, MDR, XDR, Microsoft 365, Azure, Google Workspace, Git
Responsibilities
Create, test, monitor, and tune detection rules across multiple operating systems; Conduct hypothesis-driven threat hunts on large-scale telemetry; Translate threat intelligence and IOCs into actionable detections; Build and refine hunting dashboards; Investigate and escalate ambiguous signs of attacker activity; Contribute to community projects and content creation; Validate AI-generated detection outputs
Seniority
Senior, hands-on IC