What You'll Do
- Use Red Canary’s detection platform to analyze EDR telemetry, alerts, and log sources across several detection domains (Endpoint, Identity, SIEM, Cloud/SaaS, etc.) to uncover threats and tell the story of what occurred in a customer environment.
- Publish threats for customers using concisely-written communication while effectively conveying key and important indicators
- Detector Development: Research coverage opportunities then create new detectors, and tune existing ones.
- Improve the CIRT workflow through orchestration & automation
- Provide mentorship to your peers and communicate effectively with others for efficient cross-team collaboration
- Leverage previous SOC experience to enhance the CIRT’s knowledge-base and expertise
- Actively engage with the CIRT team to challenge the status quo for detecting adversarial behavior
- Help lead projects to improve the quality of life for both the customer and the CIRT
What You'll Bring
- Analysis experience and proficiency in one or more of the following functional areas: Endpoint (MDR), Cloud/SaaS, Identity, Email, SIEM
- Proven experience with automation and orchestration to effectively handle an extreme volume of telemetry and logs in a timely and efficient manner
- Strong written communication skills, and abilities to work in a team-centric environment
- Strong analytical thought-process and critical thinking skills to translate disparate activity into the realm of threat analysis
- Open-source intelligence research skills used in a fast-paced operational environment, and the ability to apply those findings within the analytical workflow to identify threats
- Experience leveraging Mitre ATT&CK framework, and familiarity with other alternative attack frameworks and threat models
- Familiarity with backend data structures used for security analysis (JSON, YAML, etc.)
- Experience using query languages and understanding syntax across EDR or other security platforms (SQL, K, Lucene, etc.)
- Experience creating and tuning detectors/rules using commonly known tools such as YARA, SIGMA, Snort, Splunk, Elastic, etc.
Bonus Points
- You enjoy impacting the Infosec community through writing blogs, participating in webinars, and presenting at conference talks
- Experience using version control software for the deployment of detectors, rules, or other automations (GitHub, CircleCi, etc)
- Previous Red Team experience
Other Jobs from Red Canary
Staff Software Engineer (Ruby/Rails)
Similar Jobs
Software Developer
Senior Data Engineer (V)
Junior Data Engineer (V)
Senior Data Scientist
Senior Frontend Software Engineer
Data Scientist, Analytics
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 401 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say