Security Researcher - EDR

5 Days ago • 2-3 Years

About the job

SummaryBy Outscal

This role requires 2+ years of experience writing detection using Snort, Yara, Sandbox, or proprietary detection engines, performing threat hunting, and querying large datasets. Strong understanding of cybersecurity threats and the MITRE ATT&CK framework is essential. You'll analyze malware, write detection rules, and conduct threat hunting.

Job Title:

Security Researcher - EDR

About Trellix:

Trellix is a global company redefining the future of cybersecurity and soulful work. The company’s comprehensive, open and native cybersecurity platform helps organizations confronted by today’s most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through artificial intelligence, automation, and analytics to empower over 50,000 business and government customers with responsibly architected security. More at  https://trellix.com. 

Role Overview:

We are looking for a skilled EDR Security Researcher. Your primary responsibility will be to evaluate and improve our EDR product's detection capabilities by identifying detection coverage gaps and developing signatures to address these gaps effectively.

About the role:

  • Reverse engineer malware to identify malicious code, obfuscation techniques, and communication protocols.
  • Author detection rules for behavior-based detection engines.
  • Conduct deep research on attacker campaigns and techniques to support detection investments and improve customer experience.
  • Write generic threat detections based on static and dynamic detection engines.
  • Demonstrate a strong understanding of cybersecurity threats, attack techniques, and the MITRE ATT&CK framework.
  • Conduct proactive and reactive threat hunting and identify detection issues such as misses or misclassifications from a large-scale dataset.
  • Respond to escalations to resolve detection effectiveness issues (misclassifications, false positives, and false negatives).
  • Engage and collaborate with diverse partner teams to drive great customer experiences and ensure holistic protection.
  • Develop alerting, reporting, and automated detection solutions.
  • Build tools and automation to improve productivity.

About you:

  • 3+ years of experience writing detection using Snort, Yara, Sandbox, or proprietary detection engines.
  • 2+ years of experience performing threat hunting or deep familiarity with incident response procedures, processes, and tools.
  • 2+ years of experience querying and analyzing (for malware/TTPs) large datasets.
  • Experience in programming or scripting languages (e.g., Python, PowerShell).
  • Experience in utilizing various malware analysis tools and frameworks (e.g., IDA Pro).
  • Experience performing detection engineering across multiple operating systems, including Windows, Linux, and macOS.
  • Excellent verbal and written communication skills in English.

Company Benefits and Perks:

We work hard to embrace diversity and inclusion and encourage everyone to bring their authentic selves to work every day. We offer a variety of social programs, flexible work hours and family-friendly benefits to all of our employees.

  • Retirement Plans
  • Medical, Dental and Vision Coverage
  • Paid Time Off
  • Paid Parental Leave
  • Support for Community Involvement

We're serious about our commitment to diversity which is why we prohibit discrimination based on race, color, religion, gender, national origin, age, disability, veteran status, marital status, pregnancy, gender expression or identity, sexual orientation or any other legally protected status.

About The Company

Trellix is a global company redefining the future of cybersecurity. The company’s open and native extended detection and response (XDR) platform helps organizations confronted by today’s most advanced threats gain confidence in the protection and resilience of their operations. Trellix’s security experts, along with an extensive partner ecosystem, accelerate technology innovation through machine learning and automation to empower over 53,000 business and government customers. More at https://trellix.com.

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Karnataka, India (On-Site)

Germany (Remote)

View All Jobs

Similar Jobs

varonis-internal - Cloud Security Researcher

Tel Aviv District, Israel (On-Site)

Ubisoft - Security Researcher

Quebec, Canada (Hybrid)

Forcepoint - Security Researcher II

Maharashtra, India (On-Site)

Similar Skill Jobs

GoTo - Stagiaire / Intern

Canada (Remote)

Pluralsight - Strategic Growth Account Executive - DACH

County Dublin, Ireland (Hybrid)

GoTo - Stagiaire / Intern

Canada (Remote)

Pluralsight - Strategic Growth Account Executive - DACH

County Dublin, Ireland (Hybrid)

Expedia - Data Scientist I, Analytics

England, United Kingdom (Hybrid)

Nasdaq - Application Support Analyst

New South Wales, Australia (Hybrid)

Nasdaq - Senior Specialist - Agile Product Management

New South Wales, Australia (Hybrid)

Jobs in Bengaluru, Karnataka, India

Nasdaq - Lead - Project Product Owner

Karnataka, India (On-Site)

Nasdaq - Lead - Project Product Owner

Karnataka, India (On-Site)

paypal - Sr. Storage and Systems Engineer

Tamil Nadu, India (Hybrid)

paypal - Software Engineer (Fullstack)

Karnataka, India (Hybrid)

paypal - Data scientist - Payments

Tamil Nadu, India (Hybrid)

paypal - Lead Software Engineer

Karnataka, India (Hybrid)

paypal - Software Engineer

Karnataka, India (Hybrid)

paypal - Machine Learning Engineer

Tamil Nadu, India (On-Site)

Software Engineering Jobs

GoTo - Stagiaire / Intern

Canada (Remote)

GoTo - Stagiaire / Intern

Canada (Remote)

Expedia - Software Engineer

California, United States (Hybrid)

Nasdaq - Application Support Analyst

New South Wales, Australia (Hybrid)

Nasdaq - ESG Data Analyst

Metro Manila, Philippines (Hybrid)

Nasdaq - Technical Analyst, Calypso, Fintech

New South Wales, Australia (Hybrid)

Nasdaq - Senior Data Engineer - Python

Metro Manila, Philippines (Hybrid)

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug