PB✓
PBridge

Full-time jobsthe United States

macOS / Container Security - Senior Security Research Engineer

elastic · United States · Full-time

About this role

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.

What is The Role

In this role, you'll work with the Threat Research and Detection Engineering (TRaDE) team, which plays a key part in shaping the detection capabilities within Elastic Security. We're seeking a Senior Security Research Engineer who has a solid background in macOS and Kubernetes / container security, useful experience in detection engineering, and a genuine interest in enhancing defensive measures.

 

What You Will Be Doing

• Develop tailored detection analytics for endpoint macOS and Kubernetes / container environments. Validate rule functionality and minimize false positives through thorough reviews. Analyze multi-source telemetry to uncover detection opportunities and enhance clarity. Collaborate with peers to implement innovative detection methodologies and engage in community knowledge sharing.

• Emulate various threat scenarios to thoroughly assess detection capabilities. Develop and refine detection rules based on the outcomes of these simulations. Evaluate existing protection mechanisms against simulated attacks and document your findings while recommending improvements for threat detection.

• Collaborate with the engineering team to identify telemetry gaps in existing security measures. Design and implement enhancements that improve detection accuracy. Assess current telemetry data's gaps in identifying emerging threats and integrate advanced analytics to strengthen detection capabilities. Provide technical guidance on best practices for utilizing telemetry in security measures.

• Write and publish insightful blogs that focus on detection strategies and methodologies. Contribute to open-source intelligence (OSINT) research, sharing valuable findings with the community. Develop and maintain a repository of security rules and detection content. Engage with the cybersecurity community to promote knowledge sharing and best practices, and collaborate with external partners to enhance resources and tools for threat detection.

What You Bring

• Experience with detection rule development for macOS / Kubernetes / container environments

• Proficiency in using Elastic Security features and tools

• Created detection rules that reduced false positives. These rules also improved incident response performance and improved detection coverage

• Published contributions to community dete

Tired of applying one by one?

Our Career Success Team finds roles in the United States that fit you, tailors your CV to each, and submits the applications — tracked end to end. You just show up to interviews.

We apply, you interview →