JOBSEARCHER

Detection Engineer

RootedReston, VAL5 SeniorAugust 23rd, 2026
About The RoleYou translate known attacker techniques into detection rules that work against real production data. The difficulty is not writing a rule that fires on a test case; it is writing one that still identifies the technique months later while producing few enough false positives that the on-call team can trust it. You also run threat hunts to find activity that current detections would have missed.What you will doBuild detections from real attacker behaviourMeasure each rule's false positive rate and own itHunt for what current detections would have missedWhat they ask forKnows what attacks look like in telemetry, not just in theoryQuery languages and a scripting languageWilling to delete your own rules when they stop earning their placeNice to havePurple team experienceSigma rulesIncident response background