Deep understanding of Kubernetes-specific detection and security challenges
Contributions to the open-source security community or experience developing detection tooling
Experience leveraging advanced analytics or machine learning techniques in detection engineering
Please note that this role is not a typical 9-5 job. There may be instances where real-time incident response requires active participation outside business hours. On-call hours (including weekends and holidays) and all-hands-on-deck participation during active incidents are expected. If crafting sophisticated detection strategies and staying ahead of threats in a dynamic, innovative environment excites you, we’d love to connect!
Proven ability to deliver impactful projects spanning multiple technical domains and teams
Extensive experience crafting custom alert logic within industry-standard tooling, like KQL, SQL, etc
Familiarity with Kubernetes fundamentals and enthusiasm to deepen your expertise
Experience collaborating closely with Purple and Red Teams, leveraging findings to enhance detection capabilities
Solid understanding of modern TTP frameworks such as MITRE ATT&CK and Cyber Kill Chain
Proficiency in at least one query language (e.g., SQL, Splunk Query Language, HiveQL)
Competency in writing detections in multiple languages (Python, Bash, Go, JavaScript, etc.)
Strong foundational knowledge of Linux or macOS internals and their relevant event sources (eBPF, Endpoint Security Framework)
Practical experience applying and contributing to the Incident Response Lifecycle methodology