Endpoint Threat Detection Engineer

ADP, Inc.

Orlando (FL)

On-site

USD 110,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ThreatLocker is seeking a Detection Engineer to drive development and improvement of detection content for EDR and ITDR platforms. You will create and tune Sigma, YARA, and Snort rules, map detections to MITRE ATT&CK, and analyze Windows telemetry to identify opportunities.

Collaborate with Threat Analysts and Security Researchers to close detection gaps, validate logic through threat hunting, and stay current on emerging threats and best practices. This is an in-office role based in Orlando, FL.

Qualifications

  • 3+ years of information security experience.
  • 2+ years with EDR or ITDR in an enterprise environment.
  • Experience developing detection content is strongly preferred.
  • Strong understanding of the MITRE ATT&CK Framework and its application.
  • Experience creating Sigma, YARA, and Snort detection rules.
  • Strong knowledge of Windows operating systems and forensic artifacts.
  • Experience with Windows persistence, privilege escalation, defense evasion, and post-exploitation.
  • Familiarity with malware analysis, threat hunting, and vulnerability research.
  • Excellent written and verbal communication skills; able to explain technical concepts to non-technical stakeholders.
  • Ability to work independently while collaborating within a team.
  • Certs such as OSCP, GCFA, GCIH, GCIA, GCDA, GCTD, or GISP are a plus.

Responsibilities

  • Develop, test, and maintain detection content for ThreatLocker platforms.
  • Create and maintain Sigma, YARA, and Snort rules.
  • Map detections to the MITRE ATT&CK framework and improve coverage.
  • Analyze Windows telemetry and artifacts to identify opportunities.
  • Research attacker techniques including persistence, privilege escalation, defense evasion, and post-exploitation.
  • Collaborate with Threat Analysts and Security Researchers to remediate gaps.
  • Validate detection logic via threat hunting and malware analysis.
  • Tune detection content to reduce false positives.
  • Document methodologies and findings for internal teams.
  • Stay current on threats and industry best practices.
  • Role is based in Orlando, FL and is an in-office position.

Skills

Information security
EDR/ITDR knowledge
MITRE ATT&CK usage
Windows forensics
Threat hunting
Adversary emulation
Analytical thinking
Communication skills
Independent work
Team collaboration

Tools

Sigma
YARA
Snort

Job description

ThreatLocker is seeking a Detection Engineer to drive development and improvement of detection content for EDR and ITDR platforms. You will create and tune Sigma, YARA, and Snort rules, map detections to MITRE ATT&CK, and analyze Windows telemetry to identify opportunities.

Collaborate with Threat Analysts and Security Researchers to close detection gaps, validate logic through threat hunting, and stay current on emerging threats and best practices. This is an in-office role based in Orlando, FL.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: EDR/ITDR & MITRE ATT&CK Expert
Detection Engineer: EDR/ITDR & MITRE ATT&CK Expert

ThreatLocker Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 110,000 - 150,000
Detection Engineer: EDR/ITDR & MITRE Mapping
Detection Engineer: EDR/ITDR & MITRE Mapping

Threatlocker Inc • Orlando (FL)

On-site
USD 90,000 - 150,000
Detection Engineer
Detection Engineer

Threatlocker Inc • Orlando (FL)

On-site
USD 90,000 - 150,000
Detection engineer
Detection engineer

ThreatLocker Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 110,000 - 150,000
Detection Engineer
Detection Engineer

ADP, Inc. • Orlando (FL)

On-site
USD 110,000 - 140,000
Threat Intelligence Analyst: Malware & Threat Research
Threat Intelligence Analyst: Malware & Threat Research

ADP, Inc. • Orlando (FL)

On-site
USD 90,000 - 120,000
Threat Intelligence Analyst — Malware & Threat Research
Threat Intelligence Analyst — Malware & Threat Research

Threatlocker Inc • Orlando (FL)

On-site
USD 85,000 - 125,000
Senior Threat Detection Engineer — Hybrid Role
Senior Threat Detection Engineer — Hybrid Role

3M HEALTHCARE • Scottsdale (AZ)

Hybrid
USD 132,000 - 165,000
Discretionary incentive plan
Benefits
Cybersecurity Solutions Engineer - In-Office Orlando
Cybersecurity Solutions Engineer - In-Office Orlando

ThreatLocker Inc. • Orlando (FL), Northern (KY)

Hybrid
USD 90,000 - 130,000
Threat Intelligence Analyst: Malware Research & Reporting
Threat Intelligence Analyst: Malware Research & Reporting

ThreatLocker • Orlando (FL)

On-site
USD 100,000 - 140,000