macOS / Container Security - Senior Security Research Engineer
Core
Develop tailored detection analytics for endpoint macOS and Kubernetes/container environments, validate rules, and analyze multi-source telemetry to uncover detection opportunities.
Role type
Senior Security Research Engineer (Detection Engineering)
Builds
Detection rules, security analytics, and threat detection capabilities for Elastic Security
Domain
Cybersecurity, Endpoint Security, Container Security, Threat Detection
Deliverable
production ML models | product features | dashboards & analysis
Required skills
macOS security, Kubernetes/container security, detection rule development, telemetry analysis, false positive reduction, incident response, open-source intelligence (OSINT), community knowledge sharing, technical writing
Preferred skills
Published security research contributions, recognition in detection engineering, ability to rotate across projects, autonomous decision-making in distributed teams
Technologies
Elastic Security, macOS, Kubernetes
Responsibilities
Develop and validate detection rules for macOS and container environments; Analyze multi-source telemetry to identify detection gaps; Emulate threat scenarios to assess and refine detection capabilities; Collaborate with engineering teams to improve telemetry integration; Publish blogs and contribute to OSINT research; Engage with the cybersecurity community and external partners
Seniority
Senior, hands-on IC