Principal Detection Engineer - R&D

Hanover, MD or Remote USA

Dragos, Inc. logo
Dragos, Inc.
Apply now Apply later

Posted 3 weeks ago

 Dragos’ Professional Services and R&D team serves as boots-on-the-ground on solving industrial control system security challenges. We then bring that expertise back and integrate it into our software technology: The Dragos Platform. Dragos is looking for a Principal Detection Engineer to join its Research and Development team. This position serves as a technical lead guiding and mentoring a team of 4 engineers around innovative asset, vulnerability, and threat discovery with the Dragos Platform. This role works closely with Threat Operations Center, Intelligence teams and Engineering teams to drive insights in industrial protocol analysis, network situational awareness, and threat behavioral analytics for all solutions.   

Responsibilities

  • Serve as a technical leader to guide and mentor fellow teammates and maintain exceptional quality of deliverables 
  • Grow our existing repository of asset identification characterizations, protocol parsers, and threat detections for the Dragos Platform  
  • Understand open and proprietary protocols to identify software, devices, configurations, and vulnerabilities  
  • Analyze and build detection logic collected from a variety of embedded devices, firewalls, network devices, and hosts 
  • Generate innovative asset identification capabilities, protocol parsers, and threat behavior analytics for the Dragos Platform  
  • Produce network focused analytics from threat intelligence and research-generated source data 
  • Work with customers and industry partners to collect, analyze and capitalize on new host and network analytic opportunities in production environments. 

Requirements

  • Willingness to be a team player on fast-moving team focused on rapidly innovating the state of industrial security 
  • Direct experience with SCADA, DCS, building automation or other industrial control system devices and environments 
  • 10+ years in security operations, threat hunting, detection development OR offensive operations, threat emulation, security tool development 
  • Prior development experience with python, rust, ruby, go, lua, etc 
  • Awareness of common operating system internals and the ability to identify analytic opportunities 
  • Comfort working with multi-terabyte host and network datasets  
  • Applied knowledge of network communication fundamentals  
  • Adept at both verbal presentation and technical writing 

Nice to Have

  • Prior experience with either red or blue teams 
  • Ability to travel (< 25%) to customer sites to collect and analyze data 
Dragos seeks passionate, hard-working, fun-loving, small-ego, big-brained people. Our tagline is “Safeguarding Civilization” not because we think highly of ourselves, but because the problems we are solving are critically important, today and in the years to come.
We offer competitive salaries, equity, and a comprehensive benefits package including medical, dental, vision, disability, 401K and life insurance.
Dragos is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce. Come join us!
Job tags: Analytics Automation Go Industrial Lua Python Ruby SCADA Threat intelligence Vulnerabilities
Job region(s): North America Remote/Anywhere
Share this job: