CareerPlanGet AI match score →

Engineer II, Threat Detection - Windows (Hybrid)

4 Locations💼 Full-time💰 $100,000–$100,000🗓 2026-07-10 → 2026-07-30

Core

Analyze intrusions, threat campaigns, and malware to implement robust behavioral detection coverage on the Falcon sensor platform for Windows endpoints.

Role type

Mid-level detection engineer (Windows endpoint security)

Builds

High-fidelity endpoint detections deployed at global scale to mitigate attacks by criminal and nation-state actors

Domain

Cybersecurity, Endpoint Detection and Response (EDR), Windows internals

Deliverable

production ML models | product features

Required skills

Windows OS internals and APIs, behavioral malware analysis, telemetry analysis, detection rule authoring, adversary TTPs, scripting (Python/PowerShell), regex

Preferred skills

Detection content lifecycle management, MITRE ATT&CK, lab infrastructure automation, agentic AI CLIs

Technologies

Falcon sensor, Windows APIs, Python, PowerShell, regex

Responsibilities

Analyze emerging threats and malware telemetry to identify coverage gaps; Author and optimize behavioral detection rules (IOAs); Query endpoint telemetry to validate hypotheses; Monitor detection precision and tune detections; Manage detections through development to production lifecycle; Collaborate with threat intelligence and incident response teams

Seniority

Mid-level, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Workday ↗