WHAT YOU WILL DO
Research and develop sophisticated detections and behavioral analytics across multiple security landscapes – cloud, identity, endpoint, network, and application – with a focus on coverage that scales across customer environments.
Work closely with R&D, Product, and AI teams as the security authority – reviewing features, shaping designs, and ensuring security logic is sound, practical, and impactful.
Apply an AI-native approach to detection and analytics challenges – leveraging LLMs, ML signals, and AI-assisted workflows to do things that rule-based approaches can't.
Identify gaps in detection coverage and analytical capabilities, and drive those findings directly into the product roadmap.
Analyze real-world attacker techniques and translate them into detection logic, hunting content, and analytical frameworks that ship as part of the platform.
Evaluate detection quality rigorously – measuring fidelity, coverage, and performance against real attacker behavior and production telemetry.
Stay sharp on the evolving threat landscape and rapidly incorporate new techniques, campaigns, and attacker tooling into our detection library.
Contribute to external research output – blog posts, talks, open-source tooling – that reflects our depth and point of view in the security community.
6+ years of hands-on experience in detection engineering, security research or incident response – working with real production data at scale.
Deep knowledge of attacker techniques and behavior across at least 2 from: cloud, identity, endpoint, and network environments, with the ability to translate that directly into high-fidelity detection logic.
An AI-native mindset – you've built or applied AI-powered tooling in a security context (detection pipelines, alert investigation, hunting workflows) and you default to AI-powered approaches before reaching for manual ones.
Experience working within or alongside a product or engineering team – you understand how software gets built, and you know how to make your security expertise actionable for R&D and Product.
Strong coding skills (Python or similar), used for research, data analysis, detection development, and tooling.
A product-oriented approach to research – you think about scale, usability, and customer impact, not just technical correctness.
Self-directed and a strong self-learner – you don't wait to be pointed at problems, and you move fast when you find them.
Strong written and verbal communication skills in English, with the ability to explain complex security concepts clearly to both technical and non-technical audiences.












