Detection Engineer
HarfangLab · Paris, France
About The Role
Join HarfangLab, a rapidly growing cybersecurity company, as a Detection Engineer. In this role, you will be responsible for improving our EDR detection capabilities by transforming threat intelligence into actionable detections. You will continuously monitor the threat landscape, design and maintain Sigma and YARA rules, validate detection quality, and identify opportunities to strengthen the product against new attack techniques. You will work in a team of 7 people and have the autonomy to drive your own projects. Benefits include flexible remote work options, health insurance, meal vouchers, additional days off, gym subscription, and access to training and events.
- Améliorer les capacités de détection de l'EDR de l'entreprise en transformant l'intelligence sur les menaces en détections exploitables.
- Surveiller en continu le paysage des menaces, concevoir et maintenir des règles Sigma et YARA, valider la qualité de la détection.
- Développer des outils internes et des automatisations pour accélérer la recherche sur les menaces et les flux de travail d'ingénierie de détection.
- Curious, proactive, resourceful, and able to work autonomously
- Reliable, diligent, and collaborative
- Strong interest in cybersecurity and Cyber Threat Intelligence
- Passionate about learning, sharing knowledge, and discussing technical topics
- Familiar with AI-powered tools and their application to CTI activities
- Experience in system and/or network administration
- Proficient in Python with working knowledge of Rust and/or C
- Good knowledge of attack techniques and adversary tradecraft
- Fluent in French and English
- At least 2–3+ years of hands-on experience in Cyber Threat Intelligence, Detection Engineering, Malware Analysis, or a related cybersecurity field
- Experience creating and maintaining detection rules (YARA, Sigma, IDS/IPS, EDR detections). This is a key requirement for the role
- Hands-on experience in malware reverse engineering
- Strong understanding of Windows, Linux, and ideally macOS internals
- Incident Response experience
- Red Team / Penetration Testing experience
- Blue Team / SOC experience
- Experience tracking threat actors and producing actionable threat intelligence
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring