Detection Engineer: EDR/ITDR & MITRE Mapping

Threatlocker Inc

Orlando (FL)

On-site

USD 90,000 - 150,000

Full time

10 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ThreatLocker is seeking a Detection Engineer to drive the development and improvement of detection content within the ThreatLocker Detect platform. The role involves creating and maintaining detection rules for EDR and ITDR products, with alignment to the MITRE ATT&CK framework.

You will leverage telemetry from malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve coverage.

Qualifications

  • 3+ years of information security experience.
  • 2+ years with EDR/ITDR in enterprise environments.
  • Experience developing detection content preferred.
  • Strong knowledge of MITRE ATT&CK and its enterprise use.
  • Experience creating Sigma, YARA, and Snort detection rules.
  • Strong knowledge of Windows OS and forensic artifacts.

Responsibilities

  • Develop, test, and maintain detection content for ThreatLocker platforms.
  • Create and maintain Sigma, YARA, and Snort detection rules.
  • Map detections to the MITRE ATT&CK Framework and improve coverage.
  • Analyze Windows telemetry and forensic artifacts to identify detection opportunities.
  • Research attacker techniques including persistence, privilege escalation, defense evasion, and post-exploitation.
  • Collaborate with Threat Analysts and Security Researchers to remediate detection gaps.

Skills

EDR/ITDR
MITRE ATT&CK
Windows forensics
Threat hunting
Adversary emulation
Communication

Tools

Sigma rules
YARA rules
Snort rules

Job description

ThreatLocker is seeking a Detection Engineer to drive the development and improvement of detection content within the ThreatLocker Detect platform. The role involves creating and maintaining detection rules for EDR and ITDR products, with alignment to the MITRE ATT&CK framework.

You will leverage telemetry from malware analysis, vulnerability research, and proactive threat hunting to identify detection gaps and improve coverage.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: EDR/ITDR & MITRE ATT&CK Expert
Detection Engineer: EDR/ITDR & MITRE ATT&CK Expert

ThreatLocker • Orlando (FL)

On-site
USD 95,000 - 135,000
Detection Engineer
Detection Engineer

ThreatLocker • Orlando (FL)

On-site
USD 95,000 - 135,000
Detection Engineer
Detection Engineer

Threatlocker Inc • Orlando (FL)

On-site
USD 90,000 - 150,000
Senior Threat Detection Engineer — Hybrid Role
Senior Threat Detection Engineer — Hybrid Role

3M HEALTHCARE • Scottsdale (AZ)

Hybrid
USD 132,000 - 165,000
Discretionary incentive plan
Benefits
Remote Detection Engineer: Build & Automate Detections
Remote Detection Engineer: Build & Automate Detections

Binary-Defense • Houston (TX)

Remote
USD 110,000 - 170,000
Medical, dental, and vision coverage
401k match
Remote-friendly work environment
+1
Cyber Threat Detection & Forensics Engineer
Cyber Threat Detection & Forensics Engineer

Jobtailor • Denver (CO)

On-site
USD 90,000 - 130,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Threat Detection & Mitigation Engineer
Threat Detection & Mitigation Engineer

AI Chopping Block • Austin (TX), Northern (KY)

Hybrid
USD 130,000 - 180,000
Cyber Threat Detection – Forensic Engineer
Cyber Threat Detection – Forensic Engineer

Jobtailor • Denver (CO)

On-site
USD 90,000 - 130,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site