Detection Engineer (Threat Research)
We are looking for early-career detection engineers who can read a threat report and turn it into a rule that fires on the right behavior and stays quiet on everything else. We seek curious, rigorous individuals who want to learn how a threat intelligence program works from the inside.
CTI Team
The Cyber Threat Intelligence team turns knowledge of real adversaries into detection coverage for Wazuh users. We track a watchlist of threat groups, map their techniques to MITRE ATT&CK, decide which gaps to close first, and prove every claim with evidence from our emulation lab. The team is small and works in fixed functional lanes with weekly cross-review. You will work directly with the CTI director, who sets the team's priorities and reviews your work weekly. AI-assisted tooling is part of the workflow; verifying its output is part of the job.
- Remote
Job description
Your role at Wazuh
- Write and maintain Wazuh rules and decoders for adversary techniques on Windows and Linux, prioritized by the team’s threat watchlist.
- Map new and existing detection content to current MITRE ATT&CK technique and sub-technique IDs, with the supporting evidence for each mapping.
- Read threat reports and extract the observable behaviors, log sources and fields a detection needs.
- Contribute to the team’s adversary knowledge base: profiles of the threat groups most relevant to Wazuh users and the techniques they use.
- Review detections written by teammates and by AI-assisted tooling; catch false positives, wrong technique IDs and over-broad logic before release.
- Work with the validation engineer to confirm each rule fires against emulated activity and document what would evade it.
What you bring along
- 1–3 years in a SOC, detection, threat hunting or threat intelligence role.
- Working knowledge of MITRE ATT&CK, including technique IDs and how sub-techniques are structured.
- Familiarity with Windows Security/Sysmon and Linux auditd/syslog telemetry: what each log source records and what legitimate activity looks like in it.
- Experience writing detection logic in at least one format (Wazuh rules, Sigma, Elastic EQL/KQL, Splunk SPL).
- Python and Git.
- Fluent in English; you can explain a detection and its limits in a paragraph.
- The habit of checking a claim against the primary source before repeating it.
Bonus skills
- Hands-on Wazuh experience (rules, decoders, agent configuration).
- Familiarity with Atomic Red Team or Caldera.
- Basic malware or script analysis (PowerShell, bash).
- Public contributions: Sigma rules, blog posts, CTF write-ups.
We offer
- 100% remote.
- Competitive salary.
- Home office budget.
- A forward-moving career path with professional growth opportunities.
- Positive, supportive and collaborative work environment.
Skills
- Git and GitHub
- Virtualization systems (VirtualBox)
- Linux containers (Docker)
- CVE knowledge
- SOC/SIEM experience
- Security hardening
Apply for this job