Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
SentinelOne, Inc. is seeking a detection-focused engineer to translate attacker techniques into production detection rules. You will measure false positives and own the tuning process to keep detections trustworthy for on-call teams.
You will hunt for gaps where current detections miss malicious activity and improve coverage. Candidates should understand telemetry-based attack patterns, be proficient with query languages and scripting, and be willing to retire rules that no longer perform.
You translate known attacker techniques into detection rules that work against real production data. The difficulty is not writing a rule that fires on a test case; it is writing one that still identifies the technique months later while producing few enough false positives that the on-call team can trust it. You also run threat hunts to find activity that current detections would have missed.