SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Detection Engineer (EDR), Defensive Agent

Horizon3.ai - Remote - Remote - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 195,000 - 230,000 / annual

Horizon3.ai is a fast-growing remote cybersecurity company that enables organizations to proactively find, fix, and verify exploitable attack vectors before criminals exploit them. The flagship product, NodeZero, delivers production-safe autonomous pentests and assessment operations at scale across internal, external, cloud, and hybrid environments, adopted by organizations from small institutions to Global 100 enterprises. You will serve as the Senior Detection Engineer for the Defensive Agent team, positioned between Product and Engineering as the domain expert who defines what "correct" means for detection and remediation. You own the ground truth that Product, Engineering, and AI research teams depend on. This is not a coding role or a product management role—you translate blue team expertise into concrete, measurable requirements and validate that systems meet them before customers see them. Key responsibilities include: - Partner with Product to turn EDR effectiveness and tuning ambitions into buildable requirements; translate SOC workflows and pain points into prioritized outcomes; push back when proposed features would not hold up in real operations. - Define acceptance criteria for detection, effectiveness, and tuning features; validate releases against standards before deployment. - Serve as the standing domain reference for Engineering and AI research on design reviews, technique questions, and vendor behavior. - Own deep, current knowledge of major EDR and endpoint platforms at console, policy, telemetry, and API levels; maintain fluency in how detection logic, prevention policy, exclusions, and tuning work in production. - Define vendor-specific policy semantics so recommendations are consistent across platforms; track platform changes and new detection capabilities to keep coverage models current. - Define what correct tuning recommendations look like and grade agent output against that standard. - Partner with the Attack team to keep technique coverage and detection expectations grounded in current adversary tradecraft. You will influence product direction and engineering priorities without direct authority, relying primarily on written artifacts—requirements, methodology docs, labeling guides, and tuning content. You must translate fluently between engineers, AI researchers, product managers, SOC analysts, and executives. REQUIREMENTS: - 6+ years in detection engineering, security operations, incident response, or threat hunting, with meaningful time as a practitioner rather than an advisor. - Hands-on operational experience administering and tuning EDR platforms in production: writing detections, managing policy and exclusions, investigating real alerts. - Deep understanding of what a SOC actually does with EDR output. - Fluency in false positive/false negative tradeoffs, alert fatigue, and detection coverage measurement. - Strong working knowledge of MITRE ATT&CK and detection coverage frameworks, with clear perspective on where they help and mislead. - Solid understanding of post-compromise attacker behavior and how it surfaces in endpoint and identity telemetry. - Demonstrated experience shaping a product or platform as a domain expert (security vendor, internal tooling, or detection engineering function). - Ability to influence without authority and move priorities. - Exceptional technical writing skills. - Comfort translating between technical and non-technical audiences. - Scripting ability, ideally Python, to query APIs, inspect telemetry, and prototype analysis. - Comfort with SQL and reasoning over large volumes of event and telemetry data.

Similar roles