Detection Engineer

🕒 April 21

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GreyNoise Intelligence

GreyNoise Intelligence

11 - 50 employees

Founded 2017

🔒 Cybersecurity

Cybersecurity

GreyNoise Intelligence is a company providing real-time threat intelligence solutions that empower security teams to manage and prioritize cyber threats without being overwhelmed by low-priority alerts. Their platform uses a global network of proprietary sensors to filter out benign traffic and focus on identifying malicious activities, enhancing the efficiency of vulnerability management, and supporting threat hunting and security operations teams. GreyNoise is particularly adept at identifying zero-day vulnerabilities and has been a key player in protecting enterprise and government organizations from high-level threats. With a focus on separating significant threats from benign internet noise, GreyNoise offers tailored data and solutions that enhance the speed and confidence of security responses in real-time.

📋 Description

• Write and tune Intrusion Detection System rules grounded in observed network behavior. • Maintain and improve tag coverage and quality: adding new tags, fixing broken ones, and de-duplicating overlaps. • Maintain benign actor classifications and known-scanner lists so non-malicious traffic is accurately labeled. • Resolve accumulated detection issues that degrade data quality for users and customers. • Use internal CLI tooling to lint, test, and deploy detection rules and tags at scale. • Read and analyze packet captures (pcaps) and related network artifacts during routine validation and debugging. • Validate detections against real traffic and own the trade-offs between false positives and false negatives for individual rules. • Triage a steady stream of inbound detection requests, CVEs, and internal coverage questions. The team processes dozens of new items weekly. • Ensure detections are wired correctly end-to-end: from raw data through rule logic to tag output. • Flag edge cases, collisions, and unexpected behavior in tags or rules for deeper follow-up. • Work closely with researchers to keep them focused on longer-horizon projects. • Communicate clearly about what you are working on, blockers, and trade-offs when priorities shift. • Help sales, support, and customer success get faster, clearer answers on detection coverage questions.

🎯 Requirements

• Demonstrated ability to read and analyze packet captures (pcaps). • Experience writing or maintaining Suricata rules or similar network detection signatures. • Comfortable with high context-switching: moving between tags, rules, pcaps, and internal requests throughout the day. • Strong attention to detail; small mistakes in tags or rules have outsized downstream effects. • Clear, concise written communication, especially when something is broken, ambiguous, or blocked.

🏖️ Benefits

• 💵 Equity in a high-growth, Series-A startup • 👩‍⚕️ 100% covered health, dental, vision, and life plans for all employees • 6️⃣ Competitive 401k employer match of 6%, which is special for a startup. This will be 100% matched and vested from day 1 • 🏖 Flexible paid time off. To encourage time off from work and ensure overall employee health and wellness, GreyNoise strongly recommends each employee to take at least 120 hours of PTO (3 weeks) annually, including at least five consecutive business days • 🌎 Remote-first culture. While we are headquartered in the Washington DC area, we have a distributed workforce -- with the majority of our team working remotely from across the country • 💻 Equipment budget. Every new employee gets an Apple Mac laptop and a $500 stipend for any equipment accessories. • 👼 Paid family leave for all employees. We offer 4 months of paid leave (birth or adoption), plus 2 months of optional unpaid leave, so new parents have time to adjust to the new life (and work) schedule • 📚 Learning & development budget. All employees receive an annual $1,500 towards professional development related to their job function. The stipend can be applied to tuition, books, conferences, and more • 🌴 Company offsites and monthly local hangouts to encourage team bonding

Apply Now

Similar Jobs

🕒 April 21

Nebius Group

1001 - 5000

🏢 Enterprise

☁️ SaaS

Lead Systems HPC Engineer optimizing large-scale GPU clusters at Nebius, enhancing performance across hardware and software in cloud computing.

Linux

Python

Go

🕒 April 21

Independent College Bookstore Association (ICBA)

1 - 10

📚 Education

🛒 Retail

🤝 B2B

Associate Project Engineer responsible for supporting execution of AV system integration projects. Handling documentation, validation, and technical support throughout the project lifecycle.

🕒 April 21

Recruiting.com

11 - 50

🎯 Recruiter

☁️ SaaS

🤝 B2B

Senior Red Team Engineer emulating advanced threat actors to test cybersecurity controls at Cencora. Collaborating with Cyber Threat Intelligence and presenting findings to stakeholders.

Cloud

Cyber Security

Linux

MacOS

Python

Go

🕒 April 21

Ulteig

1001 - 5000

⚡ Energy

System Protection Engineer at Ulteig designing and implementing protective relay settings and studies. Plans and coordinates project phases while providing technical guidance to other engineers.

🕒 April 21

Orbital Engineering, Inc.

501 - 1000

⚡ Energy

Natural Gas Engineer supporting Natural Gas Distribution Service Operations projects throughout Colorado. Collaborating on engineering design, compliance, and quality assurance with minimal supervision.