Senior Detection Engineer

Hanover, MD or Remote USA

Dragos, Inc. logo
Dragos, Inc.
Apply now Apply later

Posted 3 weeks ago

Dragos’ Professional Services and R&D team serves as boots-on-the-ground on solving industrial control system security challenges. We then bring that expertise back and integrate it into our software technology: The Dragos Platform. Dragos is looking for a Senior Detection Engineer to join its Research and Development team. This position works closely with Threat Operations Center, Intelligence teams and Engineering teams to drive insights in industrial protocol analysis, network situational awareness, and threat behavioral analytics. 

Responsibilities

  • Generate innovative threat behavior analytics for discovering historical and emerging threats to industrial networks and devices
  • Produce network focused analytics from threat intelligence and research-generated source data
  • Work with customers and industry partners to collect, analyze and capitalize on new host and network analytic opportunities in production environments. 

Requirements

  • Willingness to be a team player on fast-moving team focused on rapidly innovating the state of industrial security
  • Working knowledge of common open source detection tools (yara, snort, zeek,  tshark)
  • Awareness of common operating system internals and the ability to identify  analytic opportunities
  • Comfort working with multi-terabyte host and network datasets
  • Experience with blue and red team security tool plugin development (Zeek NSM modules, Wireshark dissectors, Metasploit modules, Nessus plugins, etc)
  • Applied knowledge of communication fundamentals to include network and serial traffic
  • Adept at both verbal presentation and technical writing

Nice to Have

  • Experience with industrial control systems, networks and protocols
  • A solid background of operational red team and/or blue team experience
  • Working knowledge of a low-level language [C, C++, etc) and scripting language  (lua, python, etc)
  • Proficient in x86/x86_64 Intel assembly
  • Ability to travel (< 25%) to customer sites to collect and analyze data
Our mission at Dragos is to protect the world’s most critical infrastructure from adversaries who wish to do it harm. We help defend industrial organizations that provide us with the tenets of modern civilization: running water, functioning electricity, and safe industrial working environments. We are practitioners who have lived through and solved real security challenges. Our team members have responded to incidents including the Ukraine 2015 power grid attack, analyzed the CRASHOVERRIDE malware responsible for the Ukraine 2016 electric grid attack, analyzed the TRISIS malware responsible for the petrochemical facility attack in 2017, built and led the National Security Agency mission to identify nation-states breaking into ICS, and performed assessments on hundreds of assets around the world. We offer competitive salaries, equity, and a comprehensive benefits package including medical, dental, vision, disability, 401K and life insurance. Dragos is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce. Come join us!
Job tags: Analytics Blue team C ICS Industrial Lua Malware Metasploit NSM Open Source Petrochemical Python Red team Threat intelligence
Share this job: