GreyNoise Intelligence Logo

GreyNoise Intelligence

Detection Engineer

Posted 2 Days Ago
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
The Detection Engineer will create, validate, and maintain high-volume detection systems to ensure accurate datasets and customer protection. Responsibilities include writing Intrusion Detection System rules, triaging detection requests, and collaborating with researchers for efficient operations.
The summary above was generated by AI
About GreyNoise

GreyNoise Intelligence is a mission driven security startup focused on helping organizations understand and mitigate risks from Internet scanning and exploitation. GreyNoise provides real-time, verifiable intelligence on all actors scanning the Internet and how some of them are attempting to exploit vulnerabilities on assets connected to corporate networks. The intelligence is highly trusted because it’s generated from a global fleet of thousands of purpose built sensors observing the Internet. Advanced data science techniques and AI are used to process millions of observed events into real-time intelligence for customers.

The GreyNoise Global Observation Grid observes and analyzes unique threat data at-scale that no one else can. GreyNoise provides the most actionable threat intelligence against perimeter threats, so that no attack works twice.


All US based positions are fully remote within the US, with optional office attendance at our DC area headquarters, unless otherwise specified. Applicants must have US work authorization. 

Please see the specific job description for all international position locations.


The Role

GreyNoise is hiring a Detection Engineer to own the high-volume, foundational detection work that keeps our datasets accurate and our customers protected. This role is intentionally focused on operational execution: building, validating, and maintaining detections at scale.


Responsibilities:Detection and Traffic Tagging Operations
  • Write and tune Intrusion Detection System rules grounded in observed network behavior.
  • Maintain and improve tag coverage and quality: adding new tags, fixing broken ones, and de-duplicating overlaps.
  • Maintain benign actor classifications and known-scanner lists so non-malicious traffic is accurately labeled.
  • Resolve accumulated detection issues that degrade data quality for users and customers.
  • Use internal CLI tooling to lint, test, and deploy detection rules and tags at scale.
  • Read and analyze packet captures (pcaps) and related network artifacts during routine validation and debugging.
  • Validate detections against real traffic and own the trade-offs between false positives and false negatives for individual rules.
Triage and Pipeline Hygiene
  • Triage a steady stream of inbound detection requests, CVEs, and internal coverage questions. The team processes dozens of new items weekly.
  • Ensure detections are wired correctly end-to-end: from raw data through rule logic to tag output.
  • Flag edge cases, collisions, and unexpected behavior in tags or rules for deeper follow-up.
Collaboration
  • Work closely with researchers to keep them focused on longer-horizon projects.
  • Communicate clearly about what you are working on, blockers, and trade-offs when priorities shift.
  • Help sales, support, and customer success get faster, clearer answers on detection coverage questions.

What Success Looks Like
  • The backlog of smaller yet important detection work stops growing and quietly gets handled.
  • Tag and detection coverage feels predictable and systematic rather than ad hoc.
  • Internal teams get faster, clearer answers on coverage questions.
  • The rest of the research team has noticeably more uninterrupted time for complex work and bigger bets.
  • You develop reliable instincts for which detection issues matter most and can prioritize without constant direction.

Who This Role Is Good For

We are flexible on the level. This could be filled by someone in early to mid-career or by a senior practitioner willing to own operational detection work as a primary focus, with a possible path toward deeper research responsibilities over time.

Early-Career or Mid-Level
  • Comfortable with networking fundamentals and common protocols.
  • Can read pcaps today, or is eager to get to "pcaps in your sleep" quickly.
  • Understands basic security concepts: CVEs, exploit vs. vulnerability, false positives vs. false negatives.
  • Thrives on clear queues of work and shipping lots of small, concrete things.
  • Wants broad exposure to real-world internet traffic and detection engineering.
Senior
  • Strong background in detection engineering, DFIR, SOC operations, or network security.
  • Sees operational detection work as the foundation for credible research, not a stepping stone past it. Expect to own this for 6 to 9+ months before the role naturally expands.
  • Can turn vague problems into scoped, repeatable workflows.
  • Understands that high-leverage impact often comes from unglamorous, highly reliable execution.

Required Skills
  • Demonstrated ability to read and analyze packet captures (pcaps).
  • Experience writing or maintaining Suricata rules or similar network detection signatures.
  • Comfort with high context-switching: moving between tags, rules, pcaps, and internal requests throughout the day.
  • Strong attention to detail; small mistakes in tags or rules have outsized downstream effects.
  • Clear, concise written communication, especially when something is broken, ambiguous, or blocked.

Nice to Haves
  • Experience with IDS/IPS platforms, Suricata, Zeek, Sigma, Nuclei, or Snort.
  • Prior exposure to large-scale internet telemetry, threat intelligence feeds, or SOC operations.

A Few of our GreyNoise Labs Principles
  • Honesty
    • Put your best understanding of the truth first in all that you do.
  • Decency
    • Treat yourself and others with respect.
  • Opinions
    • Frame opinions using data or experience; they are still opinions.
  • Computers
    • Computers are cool, but that doesn’t mean you won’t hate them.

Benefits

💵 Equity in a high-growth, Series-A startup

👩‍⚕️ 100% covered health, dental, vision, and life plans for all employees

6️⃣ Competitive 401k employer match of 6%, which is special for a startup. This will be 100% matched and vested from day 1

🏖 Flexible paid time off. To encourage time off from work and ensure overall employee health and wellness, GreyNoise strongly recommends each employee to take at least 120 hours of PTO (3 weeks) annually, including at least five consecutive business days

🌎 Remote-first culture. While we are headquartered in the Washington DC area, we have a distributed workforce -- with the majority of our team working remotely from across the country

💻 Equipment budget. Every new employee gets an Apple Mac laptop and a $500 stipend for any equipment accessories.

👼 Paid family leave for all employees. We offer 4 months of paid leave (birth or adoption), plus 2 months of optional unpaid leave, so new parents have time to adjust to the new life (and work) schedule

📚 Learning & development budget. All employees receive an annual $1,500 towards professional development related to their job function. The stipend can be applied to tuition, books, conferences, and more

🌴 Company offsites and monthly local hangouts to encourage team bonding


GreyNoise Culture
The hallmark of any great company is a palpable and viscous culture. The most important pillars of our culture are:
  • Be transparent, honest, and objective. This is what it means to be “clinical”
  • Empathize with customers, partners, and each other
  • Learn from mistakes and share the knowledge
  • The way feedback is delivered to one another matters as much as the feedback itself
  • Good work-life balance is the key to sustained productivity
  • The measure of a team member’s effectiveness is how well the rest of the team operates in their unexpected absence
  • No such thing as a million dollar idea, only million dollar execution
  • Out-innovate our previous selves
Check out our (work-in-progress) longform culture document.
 
Explainability

Any security product that is a “black box” that asks you to blindly trust it should raise red flags - we believe the same is true of your place of work. We obviously think GreyNoise is doing something unique, but don’t take our word for it - ask any of our 150+ enterprise customers, investors, thousands of happy users, or dozens of journalists who have cited GreyNoise over the past few years.


Why You Should Work at GreyNoise 
  • You enjoy identifying and solving hard problems
  • You are comfortable taking an idea from concept to customer
  • You are open to both explaining your stance and questioning others in a clinical, open-minded, and respectful manner
  • You want to directly impact users
  • You want to grow beyond your current skill set

Apply for the job

Do you want to join our team? Then we'd love to hear about you!

Top Skills

Nuclei
Sigma
Snort
Suricata
Zeek

Similar Jobs

3 Days Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
Internship
Internship
Cloud • Information Technology • Security • Software • Cybersecurity
As a Detection Engineer Intern, you will analyze telemetry, research coverage opportunities, improve workflows, and communicate threat findings effectively.
Top Skills: CloudEdrSecurity ToolsSIEM
9 Days Ago
Remote or Hybrid
US
170K-256K Annually
Senior level
170K-256K Annually
Senior level
Cloud • Healthtech • Social Impact • Software • Biotech
The Detection and Response Engineer will investigate security events, create threat detections, scale incident response, and refine automation processes to enhance the security program as the company grows rapidly.
Top Skills: AutomationCloud EnvironmentsPython
9 Days Ago
In-Office or Remote
San Francisco, CA, USA
225K-290K Annually
Expert/Leader
225K-290K Annually
Expert/Leader
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
As a Lead Security Engineer, you will architect and manage Circle's security data platform, ensuring robust data ingestion, normalization, and response strategies while collaborating on security operations initiatives.
Top Skills: AthenaAWSGlueKafkaMskPythonS3SQL

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account