macOS / Container Security - Senior Security Research Engineer
Elastic
External ApplicationRemoteFull Time
Posted 3 hours ago4 views
About the Role
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI. What is The Role In this role, you'll work with the Threat Research and Detection Engineering (TRaDE) team, which plays a key part in shaping the detection capabilities within Elastic Security. We're seeking a Senior Security Research Engineer who has a solid background in macOS and Kubernetes / container security, useful experience in detection engineering, and a genuine interest in enhancing defensive measures. What You Will Be Doing Develop tailored detection analytics for endpoint macOS and Kubernetes / container environments. Validate rule functionality and minimize false positives through thorough reviews. Analyze multi-source telemetry to uncover detection opportunities and enhance clarity. Collaborate with peers to implement innovative detection methodologies and engage in community knowledge sharing. Emulate various threat scenarios to thoroughly assess detection capabilities. Develop and refine detection rules based on the outcomes of these simulations. Evaluate existing protection mechanisms against simulated attacks and document your findings while recommending improvements for threat detection. Collaborate with the engineering team to identify telemetry gaps in existing security measures. Design and implement enhancements that improve detection accuracy. Assess current telemetry data's gaps in identifying emerging threats and integrate advanced analytics to strengthen detection capabilities. Provide technical guidance on best practices for utilizing telemetry in security measures. Write and publish insightful blogs that focus on detection strategies and methodologies. Contribute to open-source intelligence (OSINT) research, sharing valuable findings with the community. Develop and maintain a repository of security rules and detection content. Engage with the cybersecurity community to promote knowledge sharing and best practices, and collaborate with external partners to enhance resources and tools for threat detection. What You Bring Experience with detection rule development for macOS / Kubernetes / container environments Proficiency in using Elastic Security features and tools Created detection rules that reduced false positives. These rules also improved incident response performance and improved detection coverage Published contributions to community detection content or security research Innovated and shared
Requirements
Different people approach problems differently. We need that. Elastic is an equal opportunity employer and is committed to creating an inclusive culture that celebrates different perspectives, experiences, and backgrounds. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.
We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email candidate_accessibility@elastic.co. We will reply to your request within 24 business hours of submission.
Applicants have rights under Federal Employment Laws, view posters linked below: Family and Medical Leave Act (FMLA) Poster; Pay Transparency Nondiscrimination Provision Poster; Employee Polygraph Protection Act (EPPA) Poster and Know Your Rights (Poster)
Elasticsearch develops and distributes technology and information that is subject to U.S. and other countries’ export controls and licensing requirements for individuals who are located in or are nationals of the following sanctioned countries and regions: Belarus, Cuba, Iran, North Korea, Syria, or Russia, including the Ukrainian territories annexed by Russia (The Crimea region of Ukraine, The Donetsk People's Republic (DNR), The Luhansk People's Republic (LNR), Kherson or Zaporizhzhia). If you are located in or are a national of one of the listed countries or regions, an export license may be required as a condition of your employment in this role. Please note that national origin and/or nationality do not affect eligibility for employment with Elastic.
Please see here for our Privacy Statement.