Turn this role into an interview — a resume and cover letter built around what this employer wants.
ThreatLocker is seeking a Detection Engineer to develop and improve detection content for the ThreatLocker Detect platform in an in-office Orlando role. You will create and maintain custom Sigma, YARA, and Snort rules and map detections to the MITRE ATT&CK framework.
Work with Threat Analysts and Security Researchers to identify gaps, validate logic through threat hunting and malware analysis, and stay current on emerging threats and best practices. This position is based in Orlando, FL.
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Full Time Orlando, FL, US
COMPANY OVERVIEW
ThreatLocker® is a global cybersecurity leader that stops cyberattacks before they happen. The company’s Zero Trust Platform prevents breaches from both known and unknown threats by allowing only explicitly trusted software and activity across endpoints, networks, and cloud systems. Built to deploy quickly and scale across complex environments, the platform reduces operational overhead while keeping business running uninterrupted. Headquartered in Orlando, Florida, with offices in Dublin, Dubai, and Brisbane, ThreatLocker protects over 70,000 organizations worldwide.
JOB OVERVIEW
ThreatLocker is seeking a Detection Engineer to drive the development and continuous improvement of detection content within the ThreatLocker Detect platform. This role is responsible for creating and maintaining detection rules used by our Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) products while ensuring alignment with the MITRE ATT&CK® Framework.
The Detection Engineer will leverage telemetry generated through malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve product coverage. Working closely with Threat Analysts and Security Researchers, this individual will develop high-quality detection logic that identifies evolving attacker techniques while minimizing false positives.
As a Detection Engineer, you are responsible for, but not limited to:
REQUIRED QUALIFICATIONS
WORKING CONDITIONS
The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.
Background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.
ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.