10h ago

Detection Engineer

United States

โœจ $120k-$160k / yearest.

full-timemid Remotecybersecurity

๐Ÿ›  Tech Stack

๐Ÿ’ผ About This Role

You'll own the high-volume detection work that keeps GreyNoise's datasets accurate and customers protected. Your core impact is building, validating, and maintaining detections at scale, turning vague problems into repeatable workflows and shipping lots of small, concrete things. This role is intentionally focused on operational execution rather than research.

๐ŸŽฏ What You'll Do

  • Write and tune Intrusion Detection System rules based on observed network behavior.
  • Maintain tag coverage: add new tags, fix broken ones, de-duplicate overlaps.
  • Triage inbound detection requests, CVEs, and coverage questions weekly.
  • Validate detections against real traffic and manage false positive/false negative trade-offs.

๐Ÿ“‹ Requirements

  • Packet capture analysis: read and analyze pcaps.
  • Suricata rules: experience writing or maintaining network detection signatures.
  • Context switching: move between tags, rules, pcaps, and requests throughout the day.
  • Attention to detail: small mistakes have outsized downstream effects.

โœจ Nice to Have

  • Experience with IDS/IPS platforms, Zeek, Sigma, or Snort.
  • Exposure to large-scale internet telemetry or threat intelligence feeds.

๐ŸŽ Benefits & Perks

  • ๐Ÿ’ต Equity in a high-growth Series-A startup.
  • ๐Ÿ‘ฉโ€โš•๏ธ 100% covered health, dental, vision, life for employees.
  • 6๏ธโƒฃ 401k employer match of 6% vested from day one.
  • ๐Ÿ–๏ธ Flexible PTO (recommended 3+ weeks annually).
  • ๐ŸŒŽ Remote-first culture with optional DC office.

๐Ÿ“จ Hiring Process

Estimated timeline: 2-3 weeks ยท AI estimate

  1. 1Recruiter Screenยท 30 min
  2. 2Technical Interviewยท 60 min
  3. 3Hiring Manager Interviewยท 45 min
0 0 0