ThreatLocker
Detection Engineer
Orlando, FL
Sponsorship not specifiedDetected 12 days ago
CybersecurityDetection EngineeringResearchCommunicationCritical Thinking
About the role
- ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints.
- This role is responsible for creating and maintaining detection rules used by our Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) products while ensuring alignment with the MITRE ATT&CK® Framework.
- The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage.
Responsibilities
- Working closely with Threat Analysts and Security Researchers, this individual will develop high-quality detection logic that identifies evolving attacker techniques while minimizing false positives.
Requirements
- 3+ years of experience in Information Security.
- 2+ years of experience working with Endpoint Detection and Response (EDR) or Identity Threat Detection and Response (ITDR) technologies within an enterprise environment.
- Strong understanding of the MITRE ATT&CK Framework and its application within enterprise security.
- Experience creating custom Sigma, YARA, and Snort detection rules.
- Strong knowledge of Windows operating systems and Windows forensic artifacts.
- Experience with Windows persistence mechanisms, privilege escalation, defense evasion, and parent-child process relationships.
- Familiarity with malware analysis, threat hunting, and vulnerability research.
- Familiarity with adversary emulation and post-exploitation frameworks.
- Excellent written and verbal communication skills with the ability to explain technical concepts to non-technical stakeholders.
- Ability to work independently while collaborating effectively within a team environment.
Nice to have
- Relevant certifications such as OSCP, GCFA, GCIH, GCIA, GCDA, GCTD, or GISP are a plus.
Skills
- Map detections to the MITRE ATT&CK Framework and continuously improve coverage.
- Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
- Research attacker techniques including persistence, privilege escalation, defense evasion, and post-exploitation activity.
- Tune detection content to improve accuracy while reducing false positives.
- Stay current on emerging threats, attack techniques, and industry best practices.
Benefits
- Specific vision abilities required include close vision, distance vision, depth perception, and the ability to adjust focus.
Company info
- Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.
- ThreatLocker is seeking a Detection Engineer to drive the development and continuous improvement of detection content within the ThreatLocker Detect platform.
Apply directly at ThreatLocker →Create a free account for alerts like thisView ThreatLocker immigration profile
This listing is sourced directly from ThreatLocker's careers page and normalized into a canonical job model.