Principal Security Developer
You’ll be working as a principal detection developer within Managed Detection and Response Team (MDR) reporting directly to the Director of MDR. This individual will be responsible for providing multiple teams with technical direction to deliver high value, performant solutions. They will provide technical guidance and direction to multiple teams of developers through the design, implementation, and automated/integration testing of our software. This individual will have a clear history of successful contribution to professional detection development projects; they are driven, curious, and results oriented; they can manage competing priorities as they relate to improving existing our existing codebase of detections and constantly challenge the status quo.
Some of your day-to-day responsibilities will be:
- Act as a mentor to R&D technical leaders.
- Apply broad expertise and knowledge in highly specialized fields or several related disciplines.
- Lead and contribute to the development of company objectives and principles to achieve goals in creative and effective ways. Produce specifications and determine operational feasibility.
- Work on significant and unique issues where analysis of situations or data requires an evaluation of intangibles.
- Apply conceptual thinking to understand advanced issues and implications.
- Exercise independent judgment in methods, techniques, and evaluation criteria for obtaining results.
- Accountable for results, which may impact the entire function.
- Create formal networks involving coordination among groups.
- Focus on providing thought leadership and work on broader organizational projects which require understanding of wider business, by conveying advanced information and persuading several diverse stakeholders/audiences.
- Recognized internally as a subject matter expert.
- May direct the work of others.
About You
You are a highly advanced developer who makes important product decisions regarding direction and scope. You make informed decisions about which team members should work on which areas of a project and provide technical and professional leadership for the developers as well as work closely with surface domain directors regarding strategic planning. You identify and collaborate with multiple teams or organizations and have a deep understanding of system internals, networking, and technical trends. In addition, you are comfortable presenting to the executive team.
Basic Qualifications
- 10 or more years of professional experience as a detection developer, reverse engineer, security researcher or CNO developer
- Experience with:
- Python
- OS Specific Telemetry (Windows Security/Sysmon logs, Linux, MacOS)
- Windows PowerShell Monitoring
- SIEM Detections
- EDR detections/signatures
- Suricata, Sigma and Yara Rules
- Development of anomaly and behavioral based detections
- Tuning and optimization of detections for all the above
- Experience with leading and mentoring groups of developers while contributing code independently.
- Experience designing and building detection frameworks and processes
- Experience managing and measuring security efficacy of detections
- Experience managing and measuring cost efficiency of detection frameworks
- Deep understanding of networking security principles and flows
- Experience leading Agile development teams, preferably with formal Agile training
- Preferably located in Canada or the U.S.
- Nice to have: Understanding of the Arctic Wolf service delivery model
- Nice to have: Experience with the Arctic Wolf detection framework and infrastructure
- Nice to have: Commitment to continuous learning and skills development.
- Nice to have: B.Sc. in a technical field (CS, CE, EE, Math, Physics, etc with M.Sc./PhD preferred)