Detection Engineer: EDR/ITDR & MITRE ATT&CK Expert

ThreatLocker Inc.

Orlando, Northern (FL, KY)

Hybrid

USD 110,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ThreatLocker Inc. in Orlando, FL is seeking a Detection Engineer to drive the development and continuous improvement of detection content for ThreatLocker Detect.

You will create and maintain detection rules used by our EDR and ITDR products, ensuring alignment with MITRE ATT&CK. The role involves leveraging telemetry from malware analysis, threat hunting, and collaboration with Threat Analysts to identify gaps and improve coverage while minimizing false positives.

Qualifications

  • 3+ years of information security experience.
  • 2+ years working with EDR/ITDR in enterprise environments.
  • Experience developing detection content preferred.
  • Strong understanding of MITRE ATT&CK and its enterprise use.
  • Experience creating Sigma, YARA and Snort rules.
  • Strong knowledge of Windows OS and forensic artifacts.
  • Experience with threat hunting and adversary emulation.
  • Excellent communication and ability to explain technical concepts.

Responsibilities

  • Develop, test, and maintain detection content for ThreatLocker’s EDR and ITDR platforms.
  • Create and maintain Sigma, YARA, and Snort detection rules.
  • Map detections to MITRE ATT&CK and improve coverage.
  • Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
  • Research attacker techniques including persistence, privilege escalation, defense evasion, and post-exploitation activity.
  • Collaborate with Threat Analysts and Security Researchers to remediate detection gaps.
  • Validate detections through threat hunting, malware analysis, and adversary emulation.
  • Tune detection content to reduce false positives and improve accuracy.
  • Document detection methodologies and technical findings for internal teams.

Skills

EDR/ITDR experience
MITRE ATT&CK knowledge
Sigma rules
YARA rules
Snort rules
Threat hunting
Windows forensics
Analytical thinking
Communication skills
OSCP (cert)

Tools

Sigma
YARA
Snort

Job description

ThreatLocker Inc. in Orlando, FL is seeking a Detection Engineer to drive the development and continuous improvement of detection content for ThreatLocker Detect.

You will create and maintain detection rules used by our EDR and ITDR products, ensuring alignment with MITRE ATT&CK. The role involves leveraging telemetry from malware analysis, threat hunting, and collaboration with Threat Analysts to identify gaps and improve coverage while minimizing false positives.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: EDR/ITDR & MITRE Mapping
Detection Engineer: EDR/ITDR & MITRE Mapping

Threatlocker Inc • Orlando (FL)

On-site
USD 90,000 - 150,000
Endpoint Threat Detection Engineer
Endpoint Threat Detection Engineer

ADP, Inc. • Orlando (FL)

On-site
USD 110,000 - 140,000
Detection Engineer
Detection Engineer

Threatlocker Inc • Orlando (FL)

On-site
USD 90,000 - 150,000
Detection Engineer
Detection Engineer

ADP, Inc. • Orlando (FL)

On-site
USD 110,000 - 140,000
Detection engineer
Detection engineer

ThreatLocker Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 110,000 - 150,000
Threat Intelligence Analyst: Malware & Threat Research
Threat Intelligence Analyst: Malware & Threat Research

ADP, Inc. • Orlando (FL)

On-site
USD 90,000 - 120,000
Senior Threat Detection Engineer — Hybrid Role
Senior Threat Detection Engineer — Hybrid Role

3M HEALTHCARE • Scottsdale (AZ)

Hybrid
USD 132,000 - 165,000
Discretionary incentive plan
Benefits
Threat Intelligence Analyst — Malware & Threat Research
Threat Intelligence Analyst — Malware & Threat Research

Threatlocker Inc • Orlando (FL)

On-site
USD 85,000 - 125,000
Cyber Threat Detection & Forensics Engineer
Cyber Threat Detection & Forensics Engineer

Jobtailor • Denver (CO)

On-site
USD 90,000 - 130,000
Threat Intelligence Analyst: Malware Research & Reporting
Threat Intelligence Analyst: Malware Research & Reporting

ThreatLocker • Orlando (FL)

On-site
USD 100,000 - 140,000