One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
A bachelor's degree in Computer Science or Information Security
Additional notes
This role is remote within the United States
We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits
We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas
Salary Range
Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
SIEM migration experience translating detection logic between platforms and re-pointing log sources
Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
Curiosity, strong ownership, and the appetite for growth
A willingness to travel up to 20%