Build and maintain Synapse collection pipelines through Storm queries, automation, and data models.
Diagnose and resolve complex defects in Synapse tooling and collection systems independently.
Support threat hunting and adversary tracking using telemetry and malware analysis techniques.
Dragos is a global leader in OT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first mission-driven team built on authenticity, transparency, and trust.
Act as a trusted advisor and power-user of the Dragos platform, ensuring customers get maximum value for their ICS/OT security operations.
Lead deployments both onsite and remotely, manage upgrades, patches, and configuration changes to keep systems running at peak performance.
Troubleshoot and resolve issues, provide break/fix support, and collaborate with Dragos Intelligence and Services teams on investigations.
Dragos is the global leader in operational technology (OT) cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company has a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.
Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis.
Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to close gaps in the Dragos Platform's vulnerability detection.
Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits and integrating findings into broader threat intelligence.
Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.
Design, build, and maintain static and dynamic file analysis pipelines processing artifacts at scale.
Operate and extend threat indicator enrichment systems for real-time file metadata extraction.
Build and maintain threat graph intelligence systems modeling relationships between indicators and actors.
Censys provides real-time Internet intelligence and threat insights to global governments and over 50% of the Fortune 500. They are a growing, research-driven company focused on building comprehensive maps of the internet with a collaborative culture.
Own the research-to-production pipeline, turning research artifacts into production-ready detection rules, feeds, or platform APIs.
Build and maintain threat intelligence platform components across multiple services, including distribution servers, sandbox orchestration, and rules engines.
Drive STIX 2.1 adoption as a unified output schema and TAXII 2.1 as a distribution standard, defining schemas that hold up downstream.
SecurityScorecard is the global leader in cybersecurity ratings, continuously rating over 12 million companies across 64 countries. Headquartered in New York City, the company has been recognized as a Best Workplace by Inc Magazine and a Best Place to Work in NYC, with a culture that values innovation and employee engagement.
Dragos is a global leader in operational technology (OT) cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company has a remote-first mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.
Design and optimize threat detection capabilities using SIEM, SOAR, EDR, and NDR technologies.
Develop automation playbooks and cybersecurity data solutions to improve detection accuracy.
Collaborate with customer teams to close detection gaps and adapt defenses to emerging threats.
Our partner is a cybersecurity firm focused on building threat detection capabilities for enterprise environments. They foster a collaborative, engineering-led culture with significant autonomy for engineers.
Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.
This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.
Perform investigations of security incidents using digital forensics and data analytics.
Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
Build automation and detection models to identify anomalous activity and support response efforts at scale.
Maleda Tech is a technology staffing and consulting firm that provides security engineering services. They are hiring for a contract role supporting a major technology organization.
Design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments.
Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry using detections-as-code with CI/CD and version control.
Proactively hunt for threats, operationalize threat intelligence, and contribute to incident response and automation efforts.
LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. They aspire to create a culture built on trust, care, inclusion, and fun where everyone can succeed.
Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.
DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.
Lead and mentor a team of technical account managers to drive customer success and product adoption.
Establish relationships with senior stakeholders and act as escalation point between customers and internal teams.
Work with engineering and product management to guide platform development and improve scalability.
Dragos is a global leader in operational technology (OT) cybersecurity, protecting critical infrastructure from cyber threats. The company is a remote-first, mission-driven team with a culture of authenticity, transparency, and trust.
Build and scale a world-class insider threat program, including detection logic and automation.
Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
Participate in on-call rotation and proactively hunt for threats across corporate and production environments.
Maleda Tech is a technology consulting firm specializing in security and threat detection. They operate as a fast-paced team supporting major organizations, with a focus on building and scaling insider threat programs.
Design, build, and maintain cybersecurity data pipelines using Cribl, managing data flows from source systems into SIEM and data lake platforms.
Develop and integrate connectors for security data ingestion, configure parsing, routing, and transformation, and support SIEM architecture and operations.
Troubleshoot complex pipeline issues, create documentation, and collaborate with cross-functional teams to ensure data accuracy, security, and performance.
Cribl is a cybersecurity and data engineering company that helps organizations manage and optimize security data pipelines for SIEM and data lake environments. As a growing company with a small team, they emphasize independent problem-solving, collaboration, and a culture that values technical excellence and clear communication.
Monitor threats and investigate suspicious activities using logs and detection systems.
Analyze attack patterns and build detailed threat scenarios from collected data.
Improve detection and blocking mechanisms for automated attacks and malicious behaviors.
Sigma Software is a technology company that provides advanced cybersecurity solutions and application protection services. The remote team is collaborative, experienced, and operates within European time zones.
Apply deep expertise in cyber threat intelligence, analyzing advanced threat actors and attack methodologies.
Lead strategic threat intelligence initiatives, developing methodologies and providing thought leadership.
Convey complex intelligence findings through reports and briefings to diverse technical and executive audiences.
NBCUniversal is a leading media and entertainment company, creating and distributing content across film, television, streaming, and theme parks. As a subsidiary of Comcast Corporation, it employs a large global workforce and fosters an inclusive culture with a commitment to community engagement.
Lead MLB's threat intelligence and incident response programs across the league office, 30 Clubs, and affiliates.
Manage vulnerability intelligence, digital risk monitoring, incident coordination, and forensic investigations.
Own security awareness programming and use automation to shorten research, triage, and reporting cycles.
Major League Baseball (MLB) is the most historic professional sports league in the United States and Canada. With a league office, 30 Clubs, and affiliates, MLB fosters a culture of growth, teamwork, and professionalism, empowering employees to take initiative and put the team first.
Monitor and triage alerts across endpoint, network, cloud, runtime, and identity data sources.
Perform structured investigations on escalated or ambiguous alerts to build coherent timelines.
Participate in incident response, including evidence collection and containment actions.
AlphaSense provides AI-driven market intelligence and search to help enterprises make informed decisions. The company has over 2,000 employees globally and fosters a culture of innovation and collaboration.