Senior Detection Engineer (EDR), Defensive Agent

Socket.dev

United States

Hybrid

USD 195,000 - 230,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Inclusive team
Growth opportunities
Innovative culture
Hybrid & Remote work
Competitive compensation

Job summary

Horizon3 is seeking a Senior Detection Engineer to lead the blue team voice inside the Defensible Agent team. You will define what “correct” means when an attack is detected, deciding remediation and ground truth. You will partner with Product, Engineering, and AI research to ground strategy in real-world SOC behavior.

This role emphasizes domain expertise, technical writing, and cross-functional collaboration across teams. The position supports hybrid/remote work with competitive compensation.

Qualifications

  • 6+ years in detection engineering, security operations, incident response, or threat hunting.
  • Hands-on experience administering and tuning EDR platforms in production.
  • Deep understanding of what a SOC actually does with EDR output.
  • Fluency in false positive and false negative tradeoffs, alert fatigue, and detection coverage measurement.
  • Strong working knowledge of MITRE ATT&CK and detection coverage frameworks.
  • Solid understanding of post-compromise attacker behavior and telemetry.

Responsibilities

  • Partner with Product to turn EDR effectiveness into concrete, buildable requirements.
  • Translate blue team workflows into prioritized product outcomes for SOC readiness.
  • Define acceptance criteria for detection, effectiveness, and tuning features; validate releases.
  • Serve as the standing domain reference for Engineering and AI research.
  • Own knowledge of major EDR platforms and tuning in policy, telemetry, and API level.
  • Define tuning recommendations and grade agent output against the standard.

Skills

Detection engineering
EDR tuning
MITRE ATT&CK
Scripting Python
SQL
Technical writing
Cross-functional communication

Tools

Python
SQL

Job description

Get to Know Us

Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.

We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox" security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.

What You'll Do

We're hiring a Senior Detection Engineer to be the blue team voice inside the Defensive Agent team. You'll sit between Product and Engineering as the person who defines what "correct" means. When an attack technique is detected, you decide what remediation that claim requires. Your judgment becomes the ground truth.

This is not a coding role and it is not a product management role. Product owns the roadmap, Engineering owns the implementation, and our AI researchers own how the agents reason. You own the domain truth all three depend on, and you make it concrete enough to build and measure against. If you've spent your career being the person in the room who knows how the tools really behave, this is a seat where that knowledge teaches a system instead of firefighting alerts.

PRODUCT DIRECTION & REQUIREMENTS
  • Partner with Product to turn EDR effectiveness and tuning ambitions into concrete, buildable requirements.

  • Translate blue team workflows and pain into prioritized product outcomes, and push back when a proposed feature or agent behavior would not hold up in a real SOC.

  • Define acceptance criteria for detection, effectiveness, and tuning features, and validate releases against them before customers see them.

  • Serve as the standing domain reference for Engineering and AI research: available for design reviews, technique questions, and vendor behavior questions.

EDR & DETECTION DOMAIN OWNERSHIP
  • Own deep, current knowledge of the major EDR and endpoint platforms at the console, policy, telemetry, and API level.

  • Maintain fluency in how detection logic, prevention policy, exclusions, and tuning actually work in each product, including the differences between default and hardened configurations.

  • Define the vendor-specific policy semantics, so a recommended change means the same thing across platforms that model it differently.

  • Track platform changes, new detection capabilities, and vendor guidance, and keep our coverage model current as vendors ship.

  • Define what a correct tuning recommendation looks like and grade agent output against that standard.

  • Partner with the Attack team so technique coverage and detection expectations stay grounded in current adversary tradecraft.

WHAT YOU'LL BRING
EDR & BLUE TEAM EXPERTISE
  • 6+ years in detection engineering, security operations, incident response, or threat hunting, with meaningful time spent as a practitioner rather than an advisor.

  • Hands-on operational experience administering and tuning EDR platforms in production — writing detections, managing policy and exclusions, and investigating real alerts.

  • Deep understanding of what a SOC actually does with EDR output.

  • Fluency in false positive and false negative tradeoffs, alert fatigue, and detection coverage measurement.

  • Strong working knowledge of MITRE ATT&CK and detection coverage frameworks, and a clear view of where they help and where they mislead.

  • Solid understanding of post-compromise attacker behavior and how each surfaces in endpoint and identity telemetry.

PRODUCT & COLLABORATION
  • Demonstrated experience shaping a product or platform as a domain expert, whether in a security vendor, an internal tooling team, or a detection engineering function.

  • Ability to influence without authority. You will not manage the engineers or own the roadmap, and you will still be expected to move both.

  • Exceptional technical writing. Most of your leverage here comes from written artifacts — requirements, methodology docs, labeling guides, tuning content.

  • Comfort translating between audiences: engineers, AI researchers, product managers, SOC analysts, and executives.

TECHNICAL FLUENCY
  • Enough scripting ability, ideally Python, to query APIs, inspect telemetry, and prototype an analysis.

  • Comfort with SQL and with reasoning over large volumes of event and telemetry data.

Perks of Horizon3

  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.

  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.

  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.

  • Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.

  • Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.

Compensation and Values

At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.

In accordance with various State’s transparency regulations, we provide the following salary range information for this position:

  • Base salary range: $195,000-$230,000 annually. The exact salary will be determined based on the selected candidate’s location, qualifications, experience, and relevant skills.

  • Additional compensation: All full-time roles are eligible for an equity package in the form of stock options.

You Belong Here

Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, or any other legally protected status by law.

Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth.

We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Detection Engineer (EDR), Defensive Agent
Senior Detection Engineer (EDR), Defensive Agent

Horizon3 • United States

Hybrid
USD 195,000 - 230,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Senior Backend Engineer, Security Controls
Senior Backend Engineer, Security Controls

Horizon3.ai • United States

Remote
USD 187,000 - 209,000
Inclusive Team
Growth Opportunities
Hybrid & Remote Work
+1
Senior Backend Engineer, Defensive Agent
Senior Backend Engineer, Defensive Agent

Horizon3 • United States

Hybrid
USD 199,000 - 235,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Staff Software Engineer, Defensive Agent
Staff Software Engineer, Defensive Agent

Horizon3 • United States

Hybrid
USD 229,000 - 270,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Senior Backend Engineer, Defensive Agent
Senior Backend Engineer, Defensive Agent

NightDragon Acquisition Corp. • United States

Hybrid
USD 170,000 - 235,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Staff Software Engineer, Defensive Agent
Staff Software Engineer, Defensive Agent

NightDragon Acquisition Corp. • United States

Hybrid
USD 229,000 - 270,000
Inclusive team
Growth opportunities
Innovative culture
+2
Applied AI Engineer, Autonomous Defense
Applied AI Engineer, Autonomous Defense

NightDragon Acquisition Corp. • United States

Hybrid
USD 313,000 - 369,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Senior Engineer, Back-End (Security Controls)
Senior Engineer, Back-End (Security Controls)

Horizon3 • United States

On-site
USD 200,000 - 270,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Staff Software Engineer, Defensive Agent
Staff Software Engineer, Defensive Agent

Horizon3.ai • United States

Hybrid
USD 229,000 - 270,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2
Engineering Manager, Web Application Discovery
Engineering Manager, Web Application Discovery

AI Chopping Block • Northern (KY)

Hybrid
USD 225,000 - 265,000
Inclusive Team
Growth Opportunities
Innovative Culture
+2