Detection Engineer (Threat Research)

We are looking for early-career detection engineers who can read a threat report and turn it into a rule that fires on the right behavior and stays quiet on everything else. We seek curious, rigorous individuals who want to learn how a threat intelligence program works from the inside.

CTI Team

The Cyber Threat Intelligence team turns knowledge of real adversaries into detection coverage for Wazuh users. We track a watchlist of threat groups, map their techniques to MITRE ATT&CK, decide which gaps to close first, and prove every claim with evidence from our emulation lab. The team is small and works in fixed functional lanes with weekly cross-review. You will work directly with the CTI director, who sets the team's priorities and reviews your work weekly. AI-assisted tooling is part of the workflow; verifying its output is part of the job.

Location
  • Remote
Job type
Full-time

Job description

Your role at Wazuh

  • Write and maintain Wazuh rules and decoders for adversary techniques on Windows and Linux, prioritized by the team’s threat watchlist.
  • Map new and existing detection content to current MITRE ATT&CK technique and sub-technique IDs, with the supporting evidence for each mapping.
  • Read threat reports and extract the observable behaviors, log sources and fields a detection needs.
  • Contribute to the team’s adversary knowledge base: profiles of the threat groups most relevant to Wazuh users and the techniques they use.
  • Review detections written by teammates and by AI-assisted tooling; catch false positives, wrong technique IDs and over-broad logic before release.
  • Work with the validation engineer to confirm each rule fires against emulated activity and document what would evade it.

What you bring along

  • 1–3 years in a SOC, detection, threat hunting or threat intelligence role.
  • Working knowledge of MITRE ATT&CK, including technique IDs and how sub-techniques are structured.
  • Familiarity with Windows Security/Sysmon and Linux auditd/syslog telemetry: what each log source records and what legitimate activity looks like in it.
  • Experience writing detection logic in at least one format (Wazuh rules, Sigma, Elastic EQL/KQL, Splunk SPL).
  • Python and Git.
  • Fluent in English; you can explain a detection and its limits in a paragraph.
  • The habit of checking a claim against the primary source before repeating it.

Bonus skills

  • Hands-on Wazuh experience (rules, decoders, agent configuration).
  • Familiarity with Atomic Red Team or Caldera.
  • Basic malware or script analysis (PowerShell, bash).
  • Public contributions: Sigma rules, blog posts, CTF write-ups.

We offer

  • 100% remote.
  • Competitive salary.
  • Home office budget.
  • A forward-moving career path with professional growth opportunities.
  • Positive, supportive and collaborative work environment.

Skills

  • Git and GitHub
  • Virtualization systems (VirtualBox)
  • Linux containers (Docker)
  • CVE knowledge
  • SOC/SIEM experience
  • Security hardening

Apply for this job

* This field is required

    By submitting this form, you agree to our Terms of Use and acknowledge our Privacy Statement.

    This site is protected by Turnstile and the Cloudflare Privacy Policy and Terms of Service apply.