Detection Engineer II
Core
Build and maintain network-based threat detection signatures and logic to identify cyber-attacks in hybrid and multi-cloud environments.
Role type
Mid-level IC threat detection engineer (network security)
Builds
Production detection signatures, detection logic, and threat hunting capabilities for the Vectra AI Platform
Domain
Cybersecurity, Network Security, Cloud Security
Deliverable
production ML models | product features
Required skills
Suricata signature development, Python scripting, network traffic analysis, offensive security techniques, Linux/Unix, Wireshark, Git, bash, Sigma, YARA-L
Preferred skills
OSCP, GCIA, GCDA, GSEC certifications, experience with Metasploit or Cobalt Strike, cloud and SaaS environment knowledge
Technologies
Suricata, Python, Bash, Sigma, YARA-L, Wireshark, Git, Metasploit, Cobalt Strike
Responsibilities
Analyze network traffic to identify threat patterns; Develop and maintain Suricata signatures; Simulate attacks using offensive tools to generate sample traffic; Collaborate with data scientists and researchers to improve detection accuracy; Monitor and adjust network detections; Contribute to threat hunting efforts; Participate in incident response activities
Seniority
Mid-level, hands-on IC