> Markdown version of [/jobs/ext/1403462-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/1403462-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Barracuda Networks, Inc. - **Location:** Chelmsford, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $114,000.0 - $152,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Unix, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Linux, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Network Protocols, Open Source Technology, Windows PowerShell, Security Information and Event Management, Cloud Platform System, Mitre Att&ck, Malware, Cyber Threat Analysis, Purple Team (Cyber Security), Vulnerability Analysis - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=50387b669e4dab9f ## About the Role * 5+ years of hands-on experience in offensive security, threat research, detection engineering, threat intelligence, incident response, or a closely related discipline. * Strong understanding of modern attacker tradecraft and the ability to analyze how real-world adversaries operate. * Demonstrated experience researching vulnerabilities, exploits, malware, or emerging attack techniques. * Experience translating adversary behaviors and TTPs into detection opportunities or defensive requirements. * Hands-on experience with adversary emulation, red teaming, penetration testing, or attack simulation. * Experience developing or validating detections using SIEM, EDR, XDR, network, cloud, identity, or other security telemetry. * Strong understanding of the MITRE ATT&CK framework and how to map adversary behavior to observable activity and defensive coverage. * Ability to analyze complex attack chains and determine where meaningful detection and prevention opportunities exist. * Strong scripting or programming skills in languages such as Python, PowerShell, Bash, or similar. * Hands-on experience with Windows, Unix, and Linux operating systems. * Understanding of network protocols and enterprise security architecture. * Experience working with cloud environments such as AWS or Azure. * Ability to independently research unfamiliar technologies, vulnerabilities, and attack techniques and quickly develop a working technical understanding. * Strong written and verbal communication skills, with the ability to explain technical attack behavior and security risk clearly. Highly Valued Experience * Experience building adversary emulation tooling or automated attack simulations. * Experience developing detection analytics, correlation rules, behavioral detections, or detection-as-code. * Experience with EDR/XDR, SIEM, cloud security, identity security, or network detection technologies. * Experience analyzing public vulnerability disclosures and determining practical exploitability and detection opportunities. * Experience conducting Purple Team or Attack & Defend exercises. * Experience measuring detection coverage and identifying missed adversary TTPs. * Experience with threat hunting and hypothesis-driven investigations. * Experience researching novel exploitation techniques or emerging attacker tradecraft. * Experience contributing to open-source security research, vulnerability research, or offensive security tooling. * Relevant certifications such as OSCP, OSEP, OSCE, GXPN, GCIA, GCIH, CEH, or equivalent practical experience. ## Description Barracuda is looking for a highly technical security professional to join our team with a primary focus on identifying emerging threats, understanding evolving adversarial tradecraft, and translating that knowledge into actionable detection and defensive capabilities. This role sits at the intersection of threat intelligence, detection engineering, offensive security, and adversary emulation. You will research emerging vulnerabilities, exploits, malware, intrusion techniques, and attacker behaviors to understand how modern threats are evolving and how those threats can be detected across Barracuda's security ecosystem. You will help answer a critical question for our customers and our organization: "If an attacker used this technique against us today, would we actually detect it?" You will investigate how real-world adversaries operate, identify gaps in our ability to detect their behavior, and help develop the telemetry, analytics, detections, and defensive capabilities needed to identify and disrupt them. As a secondary responsibility, you will simulate adversary behavior to validate detection capabilities and expose gaps in defensive coverage. You will safely reproduce attacker TTPs, conduct controlled attack simulations, and measure whether security controls and detections perform as expected. You will collaborate closely with Threat Intelligence, Security Operations (XDR), Incident Response, and Product teams to continuously improve Barracuda's ability to detect and respond to evolving threats. Being a team player, strong communicator, and forward-thinking security practitioner is essential for success in this role. You will be a technical leader within the team, helping mentor others and advance Barracuda's capabilities in threat-informed detection and adversary validation. What You'll Be Working On Emerging Threat & Adversarial Tradecraft Research * Research emerging cyber threats, vulnerabilities, exploits, malware, and adversary campaigns. * Analyze evolving attacker TTPs and identify new techniques that may impact Barracuda and its customers. * Track changes in adversary tradecraft and translate findings into actionable defensive requirements. * Investigate how novel attack techniques can be detected through available telemetry, security controls, and product capabilities. * Identify gaps in existing detection coverage and recommend improvements to close those gaps. * Analyze real-world attacks and incidents to identify new detection opportunities and defensive lessons. * Develop technical assessments of new threats, including attack paths, required telemetry, observable behaviors, and detection opportunities. * Collaborate with Threat Intelligence and security teams to operationalize emerging threat intelligence. Detection Development & Validation * Develop and improve detection strategies for emerging and known adversary behaviors. * Translate attacker TTPs into detection logic, analytics, behavioral indicators, and detection requirements. * Evaluate whether existing detections can reliably identify real-world adversary behavior. * Identify detection blind spots and determine what additional telemetry or analytics are required to close them. * Validate detection effectiveness through controlled testing and adversary simulation. * Measure detection coverage against relevant threat actor behaviors and attack techniques. * Partner with detection engineering and security operations teams to continuously improve detection quality and reduce missed threats. * Develop automation and tooling to improve the speed, scale, and repeatability of detection validation. Adversary Simulation & Attack Validation * Conduct controlled adversary simulations based on real-world threat intelligence and emerging attacker tradecraft. * Reproduce relevant attacker behaviors and TTPs to validate defensive capabilities. * Develop and maintain repeatable attack simulations and offensive security tooling. * Conduct Attack & Defend and Purple Team exercises to determine whether security controls can detect and respond to realistic attack scenarios. * Test new and existing detections against adversary behaviors and identify missed TTPs. * Research and safely demonstrate novel attack techniques and exploitation paths in controlled environments. * Translate offensive findings into actionable improvements for detection, monitoring, prevention, and response capabilities. * Maintain appropriate cloud-based laboratories and testing environments for adversary simulation and security research. Cross-Functional Security Research * Collaborate with Incident Response teams to understand real-world attack activity and incorporate lessons learned into detection and validation programs. * Partner with Security Operations to improve detection fidelity and operational response. * Work with Product and Engineering teams to identify opportunities to improve security visibility and defensive capabilities. * Support the development of security research, threat reports, technical assessments, and internal briefings. * Communicate complex technical findings, attack paths, detection gaps, and recommended mitigations clearly to technical and non-technical audiences. * Work collaboratively and independently on unique or special assignments that require specialized security knowledge and experience. * Mentor other security professionals and contribute to the team's technical growth and capabilities., * Identify emerging threats and adversarial techniques before they become operationally significant. * Convert threat intelligence into meaningful detection opportunities. * Discover detection blind spots before attackers exploit them. * Continuously validate that detections work against realistic adversary behavior. * Improve visibility into customer-relevant attack paths and TTPs. * Increase measurable detection coverage against relevant threats. * Strengthen the feedback loop between threat intelligence, offensive security, detection engineering, security operations, incident response, and product teams. The goal is not simply to simulate attacks. The goal is to understand how attackers are evolving, determine how we can detect them, and then prove that our defenses actually work. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)