Engineer II, Threat Detection - Windows (Hybrid)
Core
Analyze intrusions, threat campaigns, and malware to implement robust behavioral detection coverage on the Falcon sensor platform for Windows endpoints.
Role type
Mid-level detection engineer (Windows endpoint security)
Builds
High-fidelity endpoint detections deployed at global scale to mitigate attacks by criminal and nation-state actors
Domain
Cybersecurity, Endpoint Detection and Response (EDR), Windows internals
Deliverable
production ML models | product features
Required skills
Windows OS internals and APIs, behavioral malware analysis, telemetry analysis, detection rule authoring, adversary TTPs, scripting (Python/PowerShell), regex
Preferred skills
Detection content lifecycle management, MITRE ATT&CK, lab infrastructure automation, agentic AI CLIs
Technologies
Falcon sensor, Windows APIs, Python, PowerShell, regex
Responsibilities
Analyze emerging threats and malware telemetry to identify coverage gaps; Author and optimize behavioral detection rules (IOAs); Query endpoint telemetry to validate hypotheses; Monitor detection precision and tune detections; Manage detections through development to production lifecycle; Collaborate with threat intelligence and incident response teams
Seniority
Mid-level, hands-on IC