Detection Engineer

SKY VC

Orlando, Northern (FL, KY)

Hybrid

USD 110,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

ThreatLocker is seeking a Detection Engineer to develop and improve detection content for the ThreatLocker Detect platform in an in-office Orlando role. You will create and maintain custom Sigma, YARA, and Snort rules and map detections to the MITRE ATT&CK framework.

Work with Threat Analysts and Security Researchers to identify gaps, validate logic through threat hunting and malware analysis, and stay current on emerging threats and best practices. This position is based in Orlando, FL.

Qualifications

  • 3+ years of information security experience.
  • 2+ years with EDR/ITDR technologies in enterprise environments.
  • Experience developing detection content is strongly preferred.
  • Strong understanding of MITRE ATT&CK and its enterprise application.
  • Experience creating custom Sigma, YARA, and Snort rules.
  • Strong knowledge of Windows OS and forensic artifacts.
  • Familiarity with threat hunting, vulnerability research, and adversary emulation.

Responsibilities

  • Develop, test, and maintain detection content for ThreatLocker Detect platform.
  • Create and maintain Sigma, YARA, and Snort detection rules.
  • Map detections to MITRE ATT&CK framework and improve coverage.
  • Analyze Windows telemetry and artifacts to identify opportunities.
  • Collaborate with Threat Analysts and Researchers to remediate gaps.
  • Validate detection logic via threat hunting and malware analysis.
  • Document methodologies and findings for internal teams.

Skills

EDR/ITDR
MITRE ATT&CK
Analytical thinking
Threat hunting
Communication

Tools

Sigma
YARA
Snort

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Detection Engineer

Full Time Orlando, FL, US

COMPANY OVERVIEW

ThreatLocker® is a global cybersecurity leader that stops cyberattacks before they happen. The company’s Zero Trust Platform prevents breaches from both known and unknown threats by allowing only explicitly trusted software and activity across endpoints, networks, and cloud systems. Built to deploy quickly and scale across complex environments, the platform reduces operational overhead while keeping business running uninterrupted. Headquartered in Orlando, Florida, with offices in Dublin, Dubai, and Brisbane, ThreatLocker protects over 70,000 organizations worldwide.

JOB OVERVIEW

ThreatLocker is seeking a Detection Engineer to drive the development and continuous improvement of detection content within the ThreatLocker Detect platform. This role is responsible for creating and maintaining detection rules used by our Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) products while ensuring alignment with the MITRE ATT&CK® Framework.

The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage. Working closely with Threat Analysts and Security Researchers, this individual will develop high-quality detection logic that identifies evolving attacker techniques while minimizing false positives.

As a Detection Engineer, you are responsible for, but not limited to:

  • Develop, test, and maintain detection content for ThreatLocker's Endpoint Detection and Identity Threat Detection platforms.
  • Create and maintain custom Sigma, YARA, and Snort detection rules.
  • Map detections to the MITRE ATT&CK Framework and continuously improve coverage.
  • Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
  • Research attacker techniques including persistence, privilege escalation, defense evasion, and post-exploitation activity.
  • Collaborate with Threat Analysts and Security Researchers to identify and remediate detection gaps.
  • Validate detection logic through threat hunting, malware analysis, and adversary emulation.
  • Tune detection content to improve accuracy while reducing false positives.
  • Document detection methodologies and technical findings for internal teams.
  • Stay current on emerging threats, attack techniques, and industry best practices.
  • The role will be based in Orlando, FL and is an in-office position.

REQUIRED QUALIFICATIONS

  • 3+ years of experience in Information Security.
  • 2+ years of experience working with Endpoint Detection and Response (EDR) or Identity Threat Detection and Response (ITDR) technologies within an enterprise environment.
  • Experience developing detection content is strongly preferred.
  • Strong understanding of the MITRE ATT&CK Framework and its application within enterprise security.
  • Experience creating custom Sigma, YARA, and Snort detection rules.
  • Strong knowledge of Windows operating systems and Windows forensic artifacts.
  • Experience with Windows persistence mechanisms, privilege escalation, defense evasion, and parent-child process relationships.
  • Familiarity with malware analysis, threat hunting, and vulnerability research.
  • Familiarity with adversary emulation and post-exploitation frameworks.
  • Strong analytical, troubleshooting, and critical thinking skills.
  • Excellent written and verbal communication skills with the ability to explain technical concepts to non-technical stakeholders.
  • Ability to work independently while collaborating effectively within a team environment.
  • Relevant certifications such as OSCP, GCFA, GCIH, GCIA, GCDA, GCTD, or GISP are a plus.

WORKING CONDITIONS

The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.

  • Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.
  • While performing duties of this job, would occasionally require standing, walking, sitting, reaching with hands and arms, climbing or balancing, stooping or kneeling, talking and hearing, and using fingers and hands to feel objects and tools.
  • Must occasionally lift and/or move up to 25 pounds.
  • Specific vision abilities required include close vision, distance vision, depth perception, and the ability to adjust focus.

Background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.

ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Detection Engineer
Detection Engineer

ADP, Inc. • Orlando (FL)

On-site
USD 110,000 - 140,000
Detection engineer
Detection engineer

ThreatLocker Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 110,000 - 150,000
Detection Engineer
Detection Engineer

Threatlocker Inc • Orlando (FL)

On-site
USD 90,000 - 150,000
Threat analyst
Threat analyst

ThreatLocker Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 90,000 - 120,000
THREAT ANALYST
THREAT ANALYST

Threatlocker Inc • Orlando (FL)

On-site
USD 85,000 - 125,000
SECURITY ANALYST LV.1
SECURITY ANALYST LV.1

Threatlocker Inc • Orlando (FL)

On-site
USD 65,000 - 85,000
SECURITY ANALYST LV.1
SECURITY ANALYST LV.1

SKY VC • Orlando (FL), Northern (KY)

Hybrid
USD 65,000 - 90,000
Endpoint Threat Detection Engineer
Endpoint Threat Detection Engineer

ADP, Inc. • Orlando (FL)

On-site
USD 110,000 - 140,000
Security Analyst Lv.1
Security Analyst Lv.1

ThreatLocker Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 65,000 - 90,000
SECURITY ANALYST LV.1
SECURITY ANALYST LV.1

ADP, Inc. • Orlando (FL)

On-site
USD 70,000 - 100,000