Detection Engineer II

Posted 2 Days Ago
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka, IND
In-Office
Mid level
Artificial Intelligence • Security • Cybersecurity
The Role
Build and maintain network-based threat detections by analyzing network traffic, writing Suricata signatures, simulating attacks, collaborating with data scientists, tuning detections, threat hunting, and supporting incident response.
Summary Generated by Built In

Vectra® is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises.

The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond to the most advanced cyber-attacks. With 35 patents in AI-driven threat detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai. 

Position Overview

We are seeking an experienced Threat Detection Engineer to extend Vectra's detection capabilities in partnership with Data Scientists and Security Researchers who are developing our AI-driven Attack Signal.

Vectra's Attack Signal Production Group is responsible for building Vectra's core threat detection and prioritization technology, leveraging AI and other methods to alert customers to critical threats in their network and cloud environments. Threat Detection Engineers work closely with Data Scientists who are developing AI models, and Security Researchers who are researching the threat landscape and assisting modeling efforts. Detection Engineers focused on Network attack behaviors complement Vectra's coverage by building Suricata signatures, specifying detection logic in python, and utilizing other available methods.

Responsibilities and Accountabilities:

  • Analyze network traffic to identify and document threat patterns.
  • Develop and maintain network-based security signatures in Suricata.
  • Use offensive security tools and techniques to simulate attacks and generate sample network traffic.
  • Collaborate with data scientists and security researchers to support detection efforts and improve detection accuracy.
  • Continuously monitor and assess the effectiveness of network detections, making adjustments as needed.
  • Contribute to threat hunting efforts by identifying new tactics, techniques, and procedures (TTPs) used by attackers.
  • Participate in incident response activities as required.

Attitudes and Behaviors: 

  • Focus on impact and results; work on the right things and get them done 
  • Drive and resourcefulness to persevere and overcome obstacles achieving challenging goals 
  • Track record of successfully solving complex and ambiguous problems 
  • High integrity and ability to positively collaborate with others

Qualifications and Experience 

  • 4-6 years of cybersecurity experience (preferably focused on threat detection and response)
  • Expertise in writing signatures with Suricata
  • Excellent people, technical and communication skills, and the ability to work collaboratively in a team environment.
  • Advanced knowledge of common operating systems, services, networking protocols, logging, cloud and SaaS environments
  • Knowledge of attacker techniques and tools (e.g., Metasploit, Cobalt Strike), and prior operational experience leveraging threat intelligence to detect and respond to adversaries
  • Familiarity with data utilized by detection technology, for example PCAPs, flow logs, cloud logs, etc.
  • Proficiency with related languages and frameworks, e.g. bash, python, Sigma, YARA-L, Linux/Unix, Wireshark, etc.
  • Scripting, software development, engineering, and/or devops experience; experience with a source control system, preferably Git 
  • Optional certifications - OSCP, GCIA, GCDA, GSEC

Vectra provides a comprehensive total rewards package that supports the financial, physical, mental and overall health of our employees and their families. Compensation includes competitive base pay, incentive plan eligibility, and participation in the employee equity plan (stock options). Specific benefits offered varies by location, but commonly include health care insurance, income protection / life insurance, access to retirement savings plans, behavioral & emotional wellness services, generous time away from work, and a comprehensive employee recognition program.

Vectra is committed to creating a diverse environment and is proud to be an equal opportunity employer. 

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. 

 

Skills Required

  • 4-6 years of cybersecurity experience (preferably focused on threat detection and response)
  • Expertise in writing Suricata signatures
  • Experience using offensive security tools and techniques (e.g., Metasploit, Cobalt Strike) to simulate attacks
  • Advanced knowledge of operating systems, services, networking protocols, logging, cloud and SaaS environments
  • Familiarity with data used by detection tech (PCAPs, flow logs, cloud logs)
  • Proficiency with bash, python, Sigma, YARA-L, Linux/Unix, and Wireshark
  • Scripting, software development, engineering and/or DevOps experience; experience with source control systems (preferably Git)
  • Excellent interpersonal, technical, and communication skills; ability to collaborate in a team environment
  • Certifications such as OSCP, GCIA, GCDA, GSEC
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
460 Employees
Year Founded: 2011

What We Do

Vectra® is the leader in threat detection and response – from cloud and data center workloads to user and IoT devices. Its Cognito® platform accelerates threat detection and investigation using AI to enrich network metadata it collects and stores with the right context to detect, hunt and investigate known and unknown threats in real time. Vectra offers four applications on the Cognito platform to address high-priority use cases. Cognito Stream™ sends security-enriched metadata to data lakes and SIEMs. Cognito Recall™ is a cloud-based application to store and investigate threats in enriched metadata. Cognito Detect™ uses AI to reveal and prioritize hidden and unknown attackers at speed. And Cognito Detect for Office 365 and Azure AD™ finds and stops attacks in enterprise SaaS applications and the Microsoft 365 ecosystem. For more information, visit vectra.ai.

Similar Jobs

Wells Fargo Logo Wells Fargo

Senior Data Engineer

Fintech • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Wells Fargo Logo Wells Fargo

Senior Software Engineer

Fintech • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Wells Fargo Logo Wells Fargo

Lead Software Engineer

Fintech • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Similar Companies Hiring

Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
New York, New York
700 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account