Detection Engineer

North America

Corelight

Disrupt future attacks with complete network visibility, next-level analytics, faster investigations, and expert threat hunting.

View all jobs at Corelight

Apply now Apply later

Do you want to help make the world safe from cyber attack? 

At Corelight, we believe that the best approach to cybersecurity risk starts with the network.  Attackers can evade endpoint detection, firewalls and many other technologies - but they can’t avoid leaving digital footprints on the networks they traverse.  Built on open-source innovations from Zeek, Suricata and YARA and refined through years of real-world use,  Corelight transforms network footprints from physical, virtual and cloud networks into actionable insights.   Our customers use these insights to speed incident response and proactively hunt for threats.  

We are seeking a skilled, experienced Sales Engineering Director to manage a diverse team of Sales Engineers who promote, sell, and create customer satisfaction with the company’s products. You will provide guidance and a roadmap to success regarding the implementation of our products. This will include presentations, product demonstrations, assessment of potential application of Corelight solutions, and the development of account plans.   Opportunity ● Develop and maintain novel detection rules, algorithms and alerts that identify malicious and unusual activities ● Conduct threat hunting activities to identify anomalies and potential threats ● Leverage controlled environments for analyzing the operation of specific attacks and attacker techniques ● Engage with Corelight Labs, Engineering and Products personnel, and with Corelight customers, to produce and refine effective detections ● Disseminate knowledge and discoveries regarding detections via internal- and external- facing documentation and other media such as blogs ● Continuously improve detection capabilities based on emerging threats Qualifications ● 3+ years of experience in one of more of the following information security disciplines: detection engineering, threat hunting, incident response, security operations engineering   ● Demonstrated knowledge of information security tools such as Zeek, Suricata, and YARA ● Demonstrated history of creating and maintaining detection rules and capabilities ● Working knowledge of security investigation and incident response processes, particularly at enterprise-scale ● Strong analytical skills related to detection engineering, including NSM/NDS systems, threat hunting, threat identification ● Familiarity with the capabilities of threat intel, malware analysis, and digital forensics ● In-depth knowledge of networking concepts and protocols such as TCP/IP, HTTP, TLS, DNS, Kerberos, SMB ● Experience working in an Agile work environment ● Working knowledge of programming in at least two languages A note on experience We understand that no candidate is perfectly qualified for any job. Experience comes in different forms; many skills are transferable; and passion goes a long way. Even more important than your resume is a clear demonstration of skill, dedication, and the ability to thrive in a fluid and collaborative environment. We want you to learn new things in this role, and we encourage you to apply if your experience is close to what we’re looking for.

Fueled by investments from top-tier venture capital organizations such as Crowdstrike, Accel and Insight, Corelight is the fastest growing network detection and response platform in the industry.  Our customers trust us to protect mission-critical assets in leading enterprises, government, and research institutions worldwide.   We are leading the way with AI-assisted workflows, machine learning models, cloud security and SaaS-based solutions to arm defenders with the tools and knowledge they need to disrupt cyber attacks.    Our team of passionate innovators are dedicated to solving some of the toughest challenges in cybersecurity, while fostering a collaborative, inclusive, and growth-oriented culture. Corelight is committed to a geographically distributed yet connected employee base with employees working from home and office locations around the world.   At Corelight, we are proud of our diversity of background and thought, and we’re united by our strong shared culture and values.

We are looking forward to meeting you.  Check us out at www.corelight.com

 

 

Notice of Pay Transparency:
The compensation for this position may vary depending on factors such as your location, skills and experience. Depending on the nature and seniority of the role, a percentage of compensation may come in the form of a commission-based or discretionary bonus. Equity and additional benefits will also be awarded.

Compensation Range$100—$200 USD
Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Agile Cloud CrowdStrike DNS Firewalls Forensics Incident response Kerberos Machine Learning Malware NSM SaaS TCP/IP TLS

Perks/benefits: Career development Equity / stock options Salary bonus

Region: North America

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.