Senior Detection Engineer (EDR), Defensive Agent

Horizon3
•$195,000 - $230,000•Remote

About The Position

Horizon3 is seeking a Senior Detection Engineer to serve as the blue team representative within the Defensive Agent team. This role acts as a crucial link between Product and Engineering, defining "correctness" for attack technique detection and remediation. The engineer will translate domain knowledge into concrete requirements for AI researchers and engineers, ensuring the product's effectiveness and accuracy. This position is ideal for someone with extensive experience understanding how security tools truly behave and applying that knowledge to system-level improvements rather than just firefighting alerts.

Requirements

  • 6+ years in detection engineering, security operations, incident response, or threat hunting, with significant hands-on practitioner experience.
  • Hands-on operational experience administering and tuning EDR platforms in production, including writing detections, managing policy and exclusions, and investigating real alerts.
  • Deep understanding of SOC operations and how EDR output is utilized.
  • Fluency in the tradeoffs between false positives and false negatives, alert fatigue, and methods for measuring detection coverage.
  • Strong working knowledge of MITRE ATT&CK and detection coverage frameworks, understanding their strengths and limitations.
  • Solid understanding of post-compromise attacker behavior and its manifestation in endpoint and identity telemetry.
  • Demonstrated experience shaping a product or platform as a domain expert.
  • Ability to influence without direct authority.
  • Exceptional technical writing skills for requirements, methodology documents, labeling guides, and tuning content.
  • Comfort translating technical concepts between diverse audiences (engineers, AI researchers, product managers, SOC analysts, executives).
  • Scripting ability, ideally in Python, for API querying, telemetry inspection, and analysis prototyping.
  • Comfort with SQL and reasoning over large volumes of event and telemetry data.

Responsibilities

  • Partner with Product to translate EDR effectiveness and tuning ambitions into concrete, buildable requirements.
  • Translate blue team workflows and pain points into prioritized product outcomes, ensuring proposed features and agent behaviors are viable in a real SOC environment.
  • Define acceptance criteria for detection, effectiveness, and tuning features, and validate releases against these criteria before customer deployment.
  • Serve as the domain expert for Engineering and AI research teams, participating in design reviews, answering technique-related questions, and providing insights on vendor behaviors.
  • Maintain deep, current knowledge of major EDR and endpoint platforms at the console, policy, telemetry, and API levels.
  • Stay fluent in the operational aspects of detection logic, prevention policy, exclusions, and tuning across different EDR products, including variations between default and hardened configurations.
  • Define vendor-specific policy semantics to ensure consistent meaning of recommended changes across platforms.
  • Track platform changes, new detection capabilities, and vendor guidance to keep the coverage model current.
  • Define the standard for correct tuning recommendations and evaluate agent output against this standard.
  • Collaborate with the Attack team to ensure technique coverage and detection expectations are aligned with current adversary tradecraft.

Benefits

  • Health, vision & dental insurance for you and your family
  • Flexible vacation policy
  • Generous parental leave
  • Competitive salary
  • Equity package in the form of stock options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service