Detection Engineer

ThreatLocker

Orlando (FL)

On-site

USD 95,000 - 135,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ThreatLocker in Orlando, FL is seeking a Detection Engineer to drive the development and continuous improvement of detection content within the ThreatLocker Detect platform. You will create and maintain detection rules used by our EDR and ITDR products while ensuring alignment with the MITRE ATT&CK Framework.

You will develop custom Sigma, YARA, and Snort detections, map detections to MITRE ATT&CK, and continuously improve coverage.

Qualifications

  • 3+ years in Information Security.
  • 2+ years with EDR/ITDR technologies in an enterprise environment.
  • Experience developing detection content is strongly preferred.
  • Strong understanding of MITRE ATT\&CK Framework and its application in enterprise security.
  • Experience creating Sigma, YARA, and Snort detection rules.
  • Strong knowledge of Windows OS and forensic artifacts.
  • Experience with Windows persistence, privilege escalation, defense evasion, and parent–child process relationships.
  • Familiarity with malware analysis, threat hunting, and vulnerability research.
  • Adversary emulation and post‑exploitation frameworks familiarity.
  • Excellent written and verbal communication; ability to explain technical concepts to non‑technical stakeholders.

Responsibilities

  • Create, test, and maintain detection content for ThreatLocker Detect platforms.
  • Develop custom Sigma, YARA, and Snort detection rules.
  • Map detections to MITRE ATT&CK and improve coverage.
  • Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
  • Research attacker techniques including persistence, privilege escalation, defense evasion, and post‑exploitation activity.
  • Collaborate with Threat Analysts and Security Researchers to remediate gaps.
  • Validate detection logic through threat hunting, malware analysis, and adversary emulation.
  • Tune detection content to improve accuracy and reduce false positives.
  • Document detection methodologies and findings for internal teams.
  • Stay current on emerging threats and industry best practices.

Skills

EDR/ITDR experience
Threat hunting
Malware analysis
Communication skills
Independent work

Education

OSCP
GCFA
GCIH
GCIA
GCDA
GCTD
GISP

Tools

Sigma
YARA
Snort
MITRE ATT&CK knowledge

Job description

ThreatLocker® is a leader in endpoint protection technologies, providing enterprise‑level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application Allowlisting, Ringfencing™, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert solutions are leading the cybersecurity market toward a more secure approach of blocking the exploits of application vulnerabilities.

Job Overview

ThreatLocker is seeking a Detection Engineer to drive the development and continuous improvement of detection content within the ThreatLocker Detect platform. This role is responsible for creating and maintaining detection rules used by our Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) products while ensuring alignment with the MITRE ATT&CK® Framework.

Responsibilities
  • Create, test, and maintain detection content for ThreatLocker's Endpoint Detection and Identity Threat Detection platforms.
  • Develop custom Sigma, YARA, and Snort detection rules.
  • Map detections to the MITRE ATT&CK Framework and continuously improve coverage.
  • Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
  • Research attacker techniques including persistence, privilege escalation, defense evasion, and post‑exploitation activity.
  • Collaborate with Threat Analysts and Security Researchers to identify and remediate detection gaps.
  • Validate detection logic through threat hunting, malware analysis, and adversary emulation.
  • Tune detection content to improve accuracy while reducing false positives.
  • Document detection methodologies and technical findings for internal teams.
  • Stay current on emerging threats, attack techniques, and industry best practices.
  • Work in an office located in Orlando, FL.
Qualifications
  • 3+ years of experience in Information Security.
  • 2+ years of experience working with Endpoint Detection and Response (EDR) or Identity Threat Detection and Response (ITDR) technologies within an enterprise environment.
  • Experience developing detection content is strongly preferred.
  • Strong understanding of the MITRE ATT&CK Framework and its application within enterprise security.
  • Experience creating custom Sigma, YARA, and Snort detection rules.
  • Strong knowledge of Windows operating systems and Windows forensic artifacts.
  • Experience with Windows persistence mechanisms, privilege escalation, defense evasion, and parent‑child process relationships.
  • Familiarity with malware analysis, threat hunting, and vulnerability research.
  • Familiarity with adversary emulation and post‑exploitation frameworks.
  • Strong analytical, troubleshooting, and critical thinking skills.
  • Excellent written and verbal communication skills with the ability to explain technical concepts to non‑technical stakeholders.
  • Ability to work independently while collaborating effectively within a team environment.
  • Relevant certifications such as OSCP, GCFA, GCIH, GCIA, GCDA, GCTD, or GISP are a plus.
Working Conditions
  • Job is performed in an office environment with occasional travel to company offices and/or property locations.
  • Requires standing, walking, sitting, reaching, climbing, stooping, kneeling, talking, hearing, and use of fingers and hands.
  • Must occasionally lift and/or move up to 25 pounds.
  • Requires close vision, distance vision, depth perception, and the ability to adjust focus.
Equal Employment Opportunity

As set forth in ThreatLocker’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: EDR/ITDR & MITRE ATT&CK Expert
Detection Engineer: EDR/ITDR & MITRE ATT&CK Expert

ThreatLocker • Orlando (FL)

On-site
USD 95,000 - 135,000
Threat Analyst
Threat Analyst

ThreatLocker • Orlando (FL)

On-site
USD 90,000 - 120,000
Solutions Engineer
Solutions Engineer

ThreatLocker • Orlando (FL)

On-site
USD 70,000 - 110,000
Detection Engineer III
Detection Engineer III

OU Health • Oklahoma City (OK)

On-site
USD 110,000 - 140,000
PTO
401(k)
Medical and dental plans
DevOps Engineer
DevOps Engineer

ThreatLocker • Orlando (FL)

On-site
USD 100,000 - 130,000
Senior Full Stack Engineer
Senior Full Stack Engineer

ThreatLocker • Orlando (FL)

On-site
USD 85,000 - 115,000
Detection Engineer - REMOTE
Detection Engineer - REMOTE

Binary Defense • Houston (TX)

On-site
USD 110,000 - 150,000
Remote-friendly work environment
Training opportunities
401k match
+1
Detection Engineer
Detection Engineer

Openkyber • Alaska

On-site
USD 120,000 - 160,000
Detection Engineer - Machine Learning (Remote, East/Central)
Detection Engineer - Machine Learning (Remote, East/Central)

CrowdStrike • United States

On-site
USD 90,000 - 125,000
Health insurance
401k
Paid time off
+1
Detection and Response Engineer
Detection and Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Digital mental health support
+1