GreyNoise Intelligence

Detection Engineer

GreyNoise Intelligence • $90K — $130K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity or detection engineering
  • Proficient in analyzing and writing Intrusion Detection System rules
  • Ability to read packet captures (pcaps) and assess network behaviors
  • Familiarity with CVEs and fundamental security concepts
  • Strong attention to detail and clear communication skills
  • Experience with network detection tools (e.g., Suricata, Snort) preferred

Responsibilities

  • Write and tune IDS rules based on network behavior
  • Enhance and maintain tag coverage and quality
  • Classify benign traffic and maintain non-malicious actor lists
  • Address detection issues to improve data quality
  • Utilize CLI tooling to deploy detection rules efficiently
  • Analyze packet captures for validation and debugging
  • Validate detection efficacy against real traffic

Benefits

  • Equity in a high-growth, Series-A startup
  • 100% coverage of health, dental, vision, and life insurance for all employees
  • Generous 401(k) match of 6%, fully vested from day one
  • Flexible PTO policy with a recommendation of 120 hours annually
  • Remote-first work culture with a distributed team
  • Equipment budget for necessary work-from-home tools
  • Four months of paid family leave for new parents
  • Annual $1,500 learning and development budget for professional growth
  • Company offsites and monthly team bonding events
Full Job Description
The Role

GreyNoise is hiring a Detection Engineer to own the high-volume, foundational detection work that keeps our datasets accurate and our customers protected. This role is intentionally focused on operational execution: building, validating, and maintaining detections at scale.

Responsibilities:
Detection and Traffic Tagging Operations
  • Write and tune Intrusion Detection System rules grounded in observed network behavior.
  • Maintain and improve tag coverage and quality: adding new tags, fixing broken ones, and de-duplicating overlaps.
  • Maintain benign actor classifications and known-scanner lists so non-malicious traffic is accurately labeled.
  • Resolve accumulated detection issues that degrade data quality for users and customers.
  • Use internal CLI tooling to lint, test, and deploy detection rules and tags at scale.
  • Read and analyze packet captures (pcaps) and related network artifacts during routine validation and debugging.
  • Validate detections against real traffic and own the trade-offs between false positives and false negatives for individual rules.
Triage and Pipeline Hygiene
  • Triage a steady stream of inbound detection requests, CVEs, and internal coverage questions. The team processes dozens of new items weekly.
  • Ensure detections are wired correctly end-to-end: from raw data through rule logic to tag output.
  • Flag edge cases, collisions, and unexpected behavior in tags or rules for deeper follow-up.
Collaboration
  • Work closely with researchers to keep them focused on longer-horizon projects.
  • Communicate clearly about what you are working on, blockers, and trade-offs when priorities shift.
  • Help sales, support, and customer success get faster, clearer answers on detection coverage questions.


What Success Looks Like
  • The backlog of smaller yet important detection work stops growing and quietly gets handled.
  • Tag and detection coverage feels predictable and systematic rather than ad hoc.
  • Internal teams get faster, clearer answers on coverage questions.
  • The rest of the research team has noticeably more uninterrupted time for complex work and bigger bets.
  • You develop reliable instincts for which detection issues matter most and can prioritize without constant direction.


Who This Role Is Good For

We are flexible on the level. This could be filled by someone in early to mid-career or by a senior practitioner willing to own operational detection work as a primary focus, with a possible path toward deeper research responsibilities over time.
Early-Career or Mid-Level
  • Comfortable with networking fundamentals and common protocols.
  • Can read pcaps today, or is eager to get to "pcaps in your sleep" quickly.
  • Understands basic security concepts: CVEs, exploit vs. vulnerability, false positives vs. false negatives.
  • Thrives on clear queues of work and shipping lots of small, concrete things.
  • Wants broad exposure to real-world internet traffic and detection engineering.
Senior
  • Strong background in detection engineering, DFIR, SOC operations, or network security.
  • Sees operational detection work as the foundation for credible research, not a stepping stone past it. Expect to own this for 6 to 9+ months before the role naturally expands.
  • Can turn vague problems into scoped, repeatable workflows.
  • Understands that high-leverage impact often comes from unglamorous, highly reliable execution.


Required Skills
  • Demonstrated ability to read and analyze packet captures (pcaps).
  • Experience writing or maintaining Suricata rules or similar network detection signatures.
  • Comfort with high context-switching: moving between tags, rules, pcaps, and internal requests throughout the day.
  • Strong attention to detail; small mistakes in tags or rules have outsized downstream effects.
  • Clear, concise written communication, especially when something is broken, ambiguous, or blocked.


Nice to Haves
  • Experience with IDS/IPS platforms, Suricata, Zeek, Sigma, Nuclei, or Snort.
  • Prior exposure to large-scale internet telemetry, threat intelligence feeds, or SOC operations.


A Few of our GreyNoise Labs Principles
  • Honesty
    • Put your best understanding of the truth first in all that you do.
  • Decency
    • Treat yourself and others with respect.
  • Opinions
    • Frame opinions using data or experience; they are still opinions.
  • Computers
    • Computers are cool, but that doesn't mean you won't hate them.


Benefits

Equity in a high-growth, Series-A startup

100% covered health, dental, vision, and life plans for all employees

6 Competitive 401k employer match of 6%, which is special for a startup. This will be 100% matched and vested from day 1

Flexible paid time off. To encourage time off from work and ensure overall employee health and wellness, GreyNoise strongly recommends each employee to take at least 120 hours of PTO (3 weeks) annually, including at least five consecutive business days

Remote-first culture. While we are headquartered in the Washington DC area, we have a distributed workforce -- with the majority of our team working remotely from across the country

Equipment budget. Every new employee gets an Apple Mac laptop and a $500 stipend for any equipment accessories.

👼 Paid family leave for all employees. We offer 4 months of paid leave (birth or adoption), plus 2 months of optional unpaid leave, so new parents have time to adjust to the new life (and work) schedule

Learning & development budget. All employees receive an annual $1,500 towards professional development related to their job function. The stipend can be applied to tuition, books, conferences, and more

Company offsites and monthly local hangouts to encourage team bonding

About GreyNoise Intelligence

GreyNoise Intelligence is a cybersecurity company that provides real-time internet threat intelligence. The company's platform collects and analyzes data from a variety of sources to identify and track malicious activity on the internet. GreyNoise Intelligence was founded in 2017 and is headquartered in San Francisco, California.
Learn more about GreyNoise Intelligence
Size
10 employees
Industry
Founded
2017
NASDAQ

Similar Jobs

More Jobs at GreyNoise Intelligence

  • GreyNoise Intelligence
    Detection Engineer
    $90K — $130K *
    Remote
    Information Technology
    Remote in United States

More Information Technology Jobs

Find similar Detection Engineer jobs: