Description
COMPANY OVERVIEW
ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application Allowlisting, Ringfencing™, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert solutions are leading the cybersecurity market toward a more secure approach of blocking the exploits of application vulnerabilities.
JOB OVERVIEW
ThreatLocker is seeking a Detection Engineer to drive the development and continuous improvement of detection content within the ThreatLocker Detect platform. This role is responsible for creating and maintaining detection rules used by our Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) products while ensuring alignment with the MITRE ATT&CK® Framework.
The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage. Working closely with Threat Analysts and Security Researchers, this individual will develop high-quality detection logic that identifies evolving attacker techniques while minimizing false positives.
As a Detection Engineer, you are responsible for, but not limited to:
- Develop, test, and maintain detection content for ThreatLocker's Endpoint Detection and Identity Threat Detection platforms.
- Create and maintain custom Sigma, YARA, and Snort detection rules.
- Map detections to the MITRE ATT&CK Framework and continuously improve coverage.
- Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
- Research attacker techniques including persistence, privilege escalation, defense evasion, and post-exploitation activity.
- Collaborate with Threat Analysts and Security Researchers to identify and remediate detection gaps.
- Validate detection logic through threat hunting, malware analysis, and adversary emulation.
- Tune detection content to improve accuracy while reducing false positives.
- Document detection methodologies and technical findings for internal teams.
- Stay current on emerging threats, attack techniques, and industry best practices.
- The role will be based in Orlando, FL and is an in-office position.
REQUIRED QUALIFICATIONS
- 3+ years of experience in Information Security.
- 2+ years of experience working with Endpoint Detection and Response (EDR) or Identity Threat Detection and Response (ITDR) technologies within an enterprise environment.
- Experience developing detection content is strongly preferred.
- Strong understanding of the MITRE ATT&CK Framework and its application within enterprise security.
- Experience creating custom Sigma, YARA, and Snort detection rules.
- Strong knowledge of Windows operating systems and Windows forensic artifacts.
- Experience with Windows persistence mechanisms, privilege escalation, defense evasion, and parent-child process relationships.
- Familiarity with malware analysis, threat hunting, and vulnerability research.
- Familiarity with adversary emulation and post-exploitation frameworks.
- Strong analytical, troubleshooting, and critical thinking skills.
- Excellent written and verbal communication skills with the ability to explain technical concepts to non-technical stakeholders.
- Ability to work independently while collaborating effectively within a team environment.
- Relevant certifications such as OSCP, GCFA, GCIH, GCIA, GCDA, GCTD, or GISP are a plus.
WORKING CONDITIONS
The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.
- Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.
- While performing duties of this job, would occasionally require standing, walking, sitting, reaching with hands and arms, climbing or balancing, stooping or kneeling, talking and hearing, and using fingers and hands to feel objects and tools.
- Must occasionally lift and/or move up to 25 pounds.
- Specific vision abilities required include close vision, distance vision, depth perception, and the ability to adjust focus.
A background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.
ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.
Similar jobs
Est. 115,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 120,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in Zero Trust cybersecurity, delivering a unified platform that provides enterprise-grade protection across users, devices, and applications. The ThreatLocker® Platform combines…
Est. 124,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 95,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 96,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 114,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 124,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 80,000 EUR
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 114,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 114,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 124,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 124,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 55,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 114,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 55,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 114,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 55,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 85,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the wo…
Our Purpose At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them become…
Est. 117,300 USD
About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the wo…
Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We protect 200+ organizations across North America, Europe, the Middle East, Southeast Asia, A…
Est. 195,000 USD
Our Purpose At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them become…
Our Purpose At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them become…
Est. 120,000 EUR
We are looking for a Detection Engineering & Automation Lead to improve detection quality and automation so high-risk attacker behavior is identified with less noise and faster investigation. This is a unique opportu…
Est. 55,000 USD
COMPANY OVERVIEW ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application…
Est. 165,000 USD
At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care, a culture focused…
Est. 182,000 USD
At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civi…
Est. 120,000 PLN
Our Purpose At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them become…