Ingeniero de Detección

SentinelOne, Inc.

United States

Remote

USD 110,000 - 170,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SentinelOne, Inc. is seeking a detection-focused engineer to translate attacker techniques into production detection rules. You will measure false positives and own the tuning process to keep detections trustworthy for on-call teams.

You will hunt for gaps where current detections miss malicious activity and improve coverage. Candidates should understand telemetry-based attack patterns, be proficient with query languages and scripting, and be willing to retire rules that no longer perform.

Qualifications

  • Knows what attacks look like in telemetry.
  • Experience with queries and scripting languages.
  • Ability to delete rules that no longer earn their place.

Responsibilities

  • Translate attacker behaviour into production-ready detections.
  • Measure false positives and own the results.
  • Hunt for detections that current rules miss.

Skills

Threat detection
Telemetry analysis
Query languages
Scripting
Detection engineering

Tools

Sigma rules

Job description

You translate known attacker techniques into detection rules that work against real production data. The difficulty is not writing a rule that fires on a test case; it is writing one that still identifies the technique months later while producing few enough false positives that the on-call team can trust it. You also run threat hunts to find activity that current detections would have missed.

What you will do:
  • Build detections from real attacker behaviour
  • Measure each rule's false positive rate and own it
  • Hunt for what current detections would have missed
What they ask for:
  • Knows what attacks look like in telemetry, not just in theory
  • Query languages and a scripting language
  • Willing to delete your own rules when they stop earning their place
Nice to have:
  • Purple team experience
  • Sigma rules
  • Incident response background
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Arquitecto de Detección y Caza de Amenazas
Arquitecto de Detección y Caza de Amenazas

SentinelOne, Inc. • United States

Remote
USD 110,000 - 170,000
Threat Detection Engineer: Build Rules & Hunt Threats
Threat Detection Engineer: Build Rules & Hunt Threats

Rootedsec • Reston (VA)

Hybrid
USD 115,000 - 145,000
Senior Detection Engineer (EDR, Autonomous Defense)
Senior Detection Engineer (EDR, Autonomous Defense)

Horizon3 • United States

Remote
USD 120,000 - 150,000
Growth opportunities
Innovation culture
Remote-friendly
+1
Detection Engineer
Detection Engineer

Rootedsec • Reston (VA)

Hybrid
USD 115,000 - 145,000
Detection Engineer (Fully Remote)
Detection Engineer (Fully Remote)

Wilco • United States

Remote
USD 130,000 - 180,000
Senior Threat Engineer - AI-Powered Detection, Response & Continuous AI Red Teaming
Senior Threat Engineer - AI-Powered Detection, Response & Continuous AI Red Teaming

CDW • United States

On-site
USD 140,000 - 210,000
Detection Engineering SME
Detection Engineering SME

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Detection Engineering SME
Detection Engineering SME

Softthink Solutions • Washington

On-site
USD 150,000 - 210,000
Operador de Red Team
Operador de Red Team

pss | beyond cybersecurity • United States

Remote
USD 120,000 - 180,000
Published tooling
Detection Engineering SME: SIEM Rules & Threat Detection Lead
Detection Engineering SME: SIEM Rules & Threat Detection Lead

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000