Skills
About the Role
ThreatLocker is looking for a Detection Engineer to help build and continuously improve detection content in the ThreatLocker Detect platform. In this role, you will create and maintain detection rules that power our Endpoint Detection and Response (EDR) and Identity Threat Detection and Response (ITDR) capabilities, ensuring strong alignment with the MITRE ATT&CK® Framework.
Responsibilities
- Develop, validate, and maintain detection rules for EDR and ITDR products
- Continuously improve detection coverage through iteration and refinement
- Ensure detection logic maps clearly to MITRE ATT&CK® techniques and behaviors
- Collaborate with engineering and security teams to support detection effectiveness and product quality
- Support detection content lifecycle, including updates, troubleshooting, and ongoing maintenance
Requirements
- Experience building detection content, analytics, or detection rules for security monitoring
- Knowledge of endpoint and/or identity threat detection concepts
- Familiarity with the MITRE ATT&CK® Framework and mapping detections to techniques
- Strong troubleshooting skills and attention to detection performance and reliability
Benefits
- Opportunity to work on security products that protect endpoints and identities
- Be part of a team focused on continuous detection improvement
- Contribute directly to threat-informed detection content aligned with industry standards