Responsibilities
- Design, build, and improve the detection, decisioning, and response workflows that power the Wirespeed Verdict Engine
- Own complex threat detection and workflow problem spaces from investigation concept through implementation, validation, and iteration
- Translate investigative thinking and threat research into scalable detections, enrichment, triage logic, and automated decisions that improve speed, accuracy, reliability, and customer outcomes
- Analyze operational data to identify false positives, false negatives, latency issues, and opportunities to improve how entire categories of work are handled
- Continuously raise the ceiling of what the system can do autonomously, reducing manual review while improving service quality and consistency
- Support especially complex or novel cases when needed, then feed those lessons back into the system so similar situations can be handled better in the future
- Keep the customer experience front and center by ensuring Wirespeed outputs are clear, helpful, accurate, and appropriately calibrated to the customer’s situation
- Identify patterns in customer pain, confusion, or friction and use those insights to improve verdict logic, response content, and overall product behavior
- Partner closely with product, engineering, and security teams to improve platform capabilities, data quality, and operational leverage
- Help define best practices, operating principles, and technical standards for Threat Engineering work
- Document detection concepts, workflow logic, and operating principles so the team can scale knowledge
- Provide technical leadership through strong execution, sound judgment, and mentorship of less experienced teammates
Skills and Qualifications
- Significant experience in cybersecurity operations such as threat detection and response, detection engineering, incident response, threat hunting, or SOC operations
- Look for repeatable patterns, clear decision logic, and ways to scale good judgment through automation rather than repeated manual work
- Strong investigative and analytical skills, with the ability to turn ambiguous signals and messy operational problems into practical detection logic and workflow improvements
- Experience building, tuning, or maintaining automations, detections, playbooks, rules, or enrichment pipelines in security tooling
- Demonstrated ability to independently own complex technical or operational problem areas, step into ambiguity, and drive them to better outcomes
- Interest in work that is different from a traditional analyst role: improving how work gets done rather than only executing it yourself
- Strong written and verbal communication skills, including the ability to document logic and explain threats, tradeoffs, and outcomes clearly to customers and internal partners
- Ability to work closely with product, engineering, and security stakeholders
- Comfort using data to evaluate detection quality, workflow performance, and where the system needs improvement
- Preference for simple, scalable solutions and willingness to reduce unnecessary complexity or manual work
Bonus Points
- Experience working in high-volume security operations environment
- Significant experience with detection and response tooling such as SIEM, EDR, SOAR, case management, and telemetry enrichment systems
- Familiarity writing scripts or queries to support investigations, automation, or workflow analysis
- Experience improving operational quality through experimentation, measurement, and continuous iteration
- Experience in workflow design, detection engineering, automation, or security product development
- Experience mentoring fellow engineers, setting technical direction, or influencing how a team approaches detection and response problems
Compensation
US base salary for this position ranges from $100000/year to $150000/year. Consistent with applicable laws, an employee's pay within this range is based on a number of factors, which include but are not limited to relevant education, skills, job-related knowledge, qualifications, work experience, credentials, and/or geographic location.