SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Vectra is seeking a Detection Engineer II to extend its AI-driven threat detection capabilities. You will work within the Attack Signal Production Group, collaborating closely with Data Scientists developing AI models and Security Researchers investigating the threat landscape.
Key responsibilities include analyzing network traffic to identify and document threat patterns, developing and maintaining network-based security signatures in Suricata, and using offensive security tools to simulate attacks and generate sample network traffic. You will collaborate with cross-functional teams to support detection efforts and improve detection accuracy, continuously monitor the effectiveness of network detections, contribute to threat hunting by identifying new attacker tactics and techniques, and participate in incident response activities as needed.
You bring 4-6 years of cybersecurity experience, preferably focused on threat detection and response. You have expertise in writing Suricata signatures and advanced knowledge of operating systems, networking protocols, cloud and SaaS environments. You understand attacker techniques and tools (Metasploit, Cobalt Strike) and have operational experience leveraging threat intelligence. You are proficient with bash, Python, Sigma, YARA-L, Linux/Unix, and Wireshark, with scripting and software development experience. Git familiarity is expected. Optional certifications include OSCP, GCIA, GCDA, or GSEC.
You demonstrate strong people, technical, and communication skills with the ability to work collaboratively. You focus on impact and results, drive resourcefulness to overcome obstacles, have a track record of solving complex problems, and maintain high integrity in team environments.