Build, deploy, and continuously improve MITRE ATT&CK–aligned detections across cloud, endpoint, identity, email, and application telemetry with clear false-positive thresholds.
Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement.
Advance the detection-as-code platform with version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability.
Build and scale a world-class insider threat program, including detection logic and automation.
Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
Participate in on-call rotation and proactively hunt for threats across corporate and production environments.
Maleda Tech is a technology consulting firm specializing in security and threat detection. They operate as a fast-paced team supporting major organizations, with a focus on building and scaling insider threat programs.
Design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments.
Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry using detections-as-code with CI/CD and version control.
Proactively hunt for threats, operationalize threat intelligence, and contribute to incident response and automation efforts.
LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. They aspire to create a culture built on trust, care, inclusion, and fun where everyone can succeed.
Design and implement scalable detection logic to identify insider threats and data exfiltration across corporate and production environments.
Conduct proactive threat hunting and incident response, collaborating with HR, Legal, and engineering teams during complex investigations.
Develop automation and detection models using Python and SQL to strengthen security response capabilities and reduce risk exposure.
The company is a technology organization specializing in security and threat detection. They operate in a fast-paced, collaborative environment with a focus on insider threat prevention and response.
Perform investigations of security incidents using digital forensics and data analytics.
Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
Build automation and detection models to identify anomalous activity and support response efforts at scale.
Maleda Tech is a technology staffing and consulting firm that provides security engineering services. They are hiring for a contract role supporting a major technology organization.
Define and drive LinkedIn's detection strategy across endpoint, identity, cloud, and SaaS environments.
Architect and operate high-signal detection capabilities using detections-as-code, telemetry modeling, and data-driven effectiveness measures.
Provide technical leadership, mentor engineers, and drive strategic investments to improve detection fidelity, scalability, and operational efficiency.
We are the world's largest professional network, built to create economic opportunity for every member of the global workforce. We're committed to providing transformational opportunities for our own employees by investing in their growth, cultivating a culture built on trust, care, inclusion, and fun.
Build and maintain SIEM infrastructure and detection systems to identify malicious behavior across corporate and production environments.
Investigate security incidents end-to-end, including malware analysis and timeline reconstruction, and develop runbooks for scalable response.
Partner with IT to enforce security standards on employee devices and drive implementation of Zero-Trust VPN and other corporate security controls.
Quora operates two platforms: Quora, a global knowledge sharing platform, and Poe, a platform for chatting with AI language models. The company fosters a culture of transparency, idea-sharing, and collaboration among its global teams.
Provide technical and operational leadership for a Security Operations Center, monitoring threats and driving incident response.
Design and develop security tools and platforms to improve detection, response, and operational efficiency.
Mentor early-career engineers and contribute to open source security projects and industry conferences.
Jobgether uses AI-powered matching to help candidates find jobs. The company operates a fully distributed, remote-first environment with in-person team events.
Design, build, and maintain static and dynamic file analysis pipelines processing artifacts at scale.
Operate and extend threat indicator enrichment systems for real-time file metadata extraction.
Build and maintain threat graph intelligence systems modeling relationships between indicators and actors.
Censys provides real-time Internet intelligence and threat insights to global governments and over 50% of the Fortune 500. They are a growing, research-driven company focused on building comprehensive maps of the internet with a collaborative culture.
Design and continuously improve detection and alerting controls to reduce noise and enable rapid response.
Build, test, and automate incident response playbooks to increase efficiency across the incident lifecycle.
Drive prioritization of alerts using a data-driven triage framework aligned with business impact and threat context.
Sword builds AI to heal billions, pioneering AI Care for healthcare delivery across physical therapy, women’s health, and more. With over 700,000 members and 1,000+ enterprise clients, they have raised $500 million and emphasize a culture of proactive security and AI proficiency.
Analyze and investigate existing detection logic built on multiple interconnected signals and rule-based expressions.
Understand and map complex data flows, processing pipelines, and dependencies across enterprise systems.
Propose simplification and optimization approaches while preserving detection quality and operational effectiveness.
Sigma Software is a global cybersecurity company delivering enterprise-grade security and risk mitigation solutions. They operate in a data-driven environment with large-scale signal processing and detection systems, working with experienced international teams in a fast-paced setting.
Contribute to the development, tuning, and maintenance of security monitoring and detection capabilities across SIEM, EDR, and cloud platforms.
Support the onboarding, integration, and testing of security data sources and telemetry feeds.
Collaborate with threat intelligence and incident response teams to translate requirements into effective detection mechanisms.
Talan is an international consulting group specializing in innovation and business transformation through technology. With over 7,200 consultants in 21 countries and a turnover of €850M, they are committed to delivering impactful, future-ready solutions.
Own multi-terabyte-per-day log pipelines across AWS and GCP, including ingest, enrichment, schema management, and cost control.
Model security data and tune query performance in Snowflake, BigQuery, and Redshift for detection engineering.
Build automation, AI agents, and infrastructure as code to support cyber defense and incident response.
DoorDash is a technology and logistics company that connects consumers, merchants, and Dashers through its delivery network. It is a large, rapidly growing company with a culture of empowerment and inclusion, committed to supporting employee well-being.
Design, implement, and maintain internal tooling for acquiring and parsing recaptured underground data.
Build and deploy cloud infrastructure using Infrastructure as Code technologies.
Collaborate with the research team to support targeting and collection of new data sources.
SpyCloud transforms recaptured darknet data to disrupt cybercrime. They have over 250 cybersecurity experts and foster a collaborative, innovative culture.
Monitor security alerts and events to identify potential threats and vulnerabilities.
Detect and analyze security incidents using multiple security tools like SIEM, EDR, and IDS/IPS.
Respond to security incidents promptly following established procedures and perform phishing analysis.
Zscaler accelerates digital transformation so customers can be more agile, efficient, resilient, and secure with its Zero Trust Exchange platform. The company employs thousands globally and fosters a culture of ownership, collaboration, and continuous feedback.
Create ICS-focused threat detections and asset identification analytics based on threat intelligence.
Mentor detection engineers and contribute to detection development initiatives.
Analyze cyber threat intelligence and network data to identify and respond to OT threats.
Dragos is the global leader in operational technology (OT) cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across multiple continents built on authenticity, transparency, and trust.
Configure and support data ingestion from various sources using APIs, webhooks, syslog, and more.
Develop and maintain pipelines for collection, routing, filtering, enrichment, and transformation.
Validate data completeness and troubleshoot issues, while documenting flows and recommendations.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations minimize risk. It is a rapidly growing, privately-held company with over 1,300 employees, known for its collaborative culture and mentorship.
Monitor and analyze sophisticated cyber threats targeting Anduril's products, infrastructure, and personnel.
Research and anticipate emerging technical trends in the threat landscape, collaborating with detection and response teams.
Enhance tooling for threat actor tracking and intelligence data integration, engaging with external partners.
Anduril Industries is a defense technology company focused on transforming military capabilities with advanced technology, including AI-powered systems and autonomy. The company is known for its fast-paced, innovative culture and its commitment to bringing cutting-edge solutions to the defense industry.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.
Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.
Design, build, and maintain cybersecurity data pipelines using Cribl, managing data flows from source systems into SIEM and data lake platforms.
Develop and integrate connectors for security data ingestion, configure parsing, routing, and transformation, and support SIEM architecture and operations.
Troubleshoot complex pipeline issues, create documentation, and collaborate with cross-functional teams to ensure data accuracy, security, and performance.
Cribl is a cybersecurity and data engineering company that helps organizations manage and optimize security data pipelines for SIEM and data lake environments. As a growing company with a small team, they emphasize independent problem-solving, collaboration, and a culture that values technical excellence and clear communication.
Combine security operations, software engineering, and site reliability to protect complex digital infrastructure.
Design, build, and operate security platforms, tooling, and automation for threat detection and incident response.
Mentor engineers, influence operational strategy, and contribute to open source security initiatives.
They build and operate a world-class Security Operations function. They are a distributed, agile engineering organization that values technical excellence and continuous learning.