SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 152,000 - 0 / annual
Dragos is seeking a Senior Detection Engineer to join its Detection Engineering team, which plays a pivotal role in helping customers identify and respond to threats targeting their operational technology (OT) environments. The role involves translating cyber threat intelligence into high-fidelity, performant detections backed by the industry's largest team of industrial control systems (ICS) cybersecurity practitioners.
As a Senior Detection Engineer, you will study emerging threats to ICS environments and create atomic, component, and composite detections for the Dragos Platform. You will be self-motivated, creative in solving complex technical challenges, and able to align with adversary thinking and the ICS Cyber Kill Chain to predict attack outcomes. You will work on a fast-moving team focused on rapidly innovating industrial security, openly sharing information to enhance team knowledge and continuously expanding your understanding of ICS technologies.
Key responsibilities include:
- Create ICS-focused threat detections and Asset Identification analytics based on assigned tickets
- Mentor Detection Engineers by engaging them in your detection development process and delegating portions of work they are ready to own
- Engage with Principal Detection Engineers to support detection development initiatives through analysis of packet captures and Windows host logs
- Test, validate, and tune detections created by the Intel Detection team for analytic quality control
- Lead review, triage, and response for detection requests submitted to the Intel Detection Support board
- Drive documentation of processes for authoring, validating, and testing analytics released in Dragos Platform Knowledge Packs
- Analyze artifacts collected from ICS equipment, embedded devices, firewalls, network devices, and ICS software
- Analyze cyber threat intelligence reporting to create detection ideation tasks
- Partner with Engineering, OT Watch, and Quality Engineering teams to identify protocol coverage gaps and resolve detection issues
- Give and receive peer feedback as part of the review cycle
Requirements:
- 8+ years in security operations, threat hunting, or detection development, OR offensive operations, threat emulation, or security tool development
- 2+ years of experience operationalizing cyber threat intelligence to defend networks from emerging threats
- 1+ years of direct experience with SCADA, DCS, building automation, or other industrial control system devices and environments
- Advanced network packet analysis and manipulation using tools such as Wireshark, Tshark, ngrep, tcpdump, Zeek, and Scapy
- Working knowledge of Windows Event Logging fundamentals, including enabling and reviewing event logs, adjusting log size and retention settings, and enabling Advanced Audit Policies
- Awareness of common operating system internals and ability to identify analytic opportunities
- Comfortable working with multi-gigabyte host and network datasets
- Applied knowledge of network communication fundamentals
- Proven ability to mentor and develop junior detection engineers
- Adept at both verbal presentation and technical writing
Preferred qualifications include experience creating detections using Suricata, Snort, YARA, or Zeek; producing cyber threat intelligence reports; programming in Python, Rust, Ruby, Go, or Lua; SOC platforms such as Splunk or Elasticsearch; AI tools in detection workflows; ICS network assessments or penetration testing; Windows and Linux system administration; cybersecurity certifications (SANS GICSP, GRID, GCTI, GCIA, GCIH, GCDA, Offensive Security OSCP/OSEP/OSED, CompTIA CySA+ or PenTest+); and ability to travel less than 10% for team activities, conferences, and customer sites.