INTL India - Remote Detection Engineer
Role details
Job location
Tech stack
Requirements
5+ years of hands-on detection engineering experience (writing production detection rules and understand correlation)
-MITRE ATT&CK fluency - ability to think in techniques and map a red team finding to a detection gap
Knowledge of SPL - you can write effective Splunk searches and understand what makes a rule expensive or fragile
-Experience with at least one EDR platform at a detection level - CrowdStrike Falcon, Microsoft Defender for Endpoint, etc.
-Understanding of offensive security techniques (understand how attacks work at a technique level)
-Experience validating detections - atomic testing, purple team participation, or equivalent empirical validation methods
-Ability to work with incomplete data - can make a coverage decision with imperfect information and document the reasoning -Purple team experience - either as a detection-side participant or having run exercises end-to-end
-Sigma rule authoring - vendor-agnostic detection development and the ability to translate rules across platforms
-Threat intelligence integration - consuming threat intel and translating it into detection requirements
-Risk-based alerting - understanding how to score and prioritize alerts rather than treating all alerts equally
-Offensive security background or certifications (OSCP, CRTE, or similar)
-Experience with CrowdStrike Falcon detection authoring specifically
-Familiarity with MITRE ATLAS for AI/ML threat scenarios
-Scripting ability (Python) - for detection automation, log parsing, or tooling integrations
-Experience writing or reviewing logging standards, detection standards, or security governance documentation
Benefits & conditions
$10/hr to $15/hr
Exact compensation may vary based on several factors, including skills, experience, and education.
Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401K retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.