A SaaS? tool that turns threat intelligence and security telemetry into prioritized detection-rule improvements for security teams.
Added Jun 8, 2026
Security teams are expected to continuously analyze threat intelligence, telemetry, anomalies, and emerging attack vectors, then translate those findings into better detection and response coverage. This work is data-heavy, repetitive, and often depends on scarce analysts who can connect threat research with actionable detection engineering.
The product ingests threat intelligence feeds, security telemetry, detection rules, and incident data to identify emerging patterns and coverage gaps. It recommends prioritized detection improvements, ML?-backed anomaly hypotheses, and risk-ranked rule updates that analysts can review and push into existing SIEM, EDR, or cloud security workflows.
Job postings repeatedly show companies investing in large-scale telemetry analysis, ML?-based threat detection, anomaly detection, and proactive threat hunting. The threat landscape is changing quickly enough that manual detection tuning is becoming a bottleneck.
Showing 1-20 of 20 signals
Leverage AI and machine learning capabilities to accelerate hypothesis generation, anomaly detection, and the analysis of large, complex datasets during hunts. Translate hunt findings into production-ready detections, collaborating closely with Detection Engineering to ensure durable coverage.
Integrate security automation platforms and intelligent workflows to streamline threat analysis and accelerate operational response capabilities. What This Role is Not This isn't a routine SOC analyst or Tier 1 triage job, you will focus on proactive threat hunting, deep adversary pursuit, and advanced detection engineering.
Design, develop, and maintain high-fidelity detection rules, correlation rules, alerts, and security use cases for newly onboarded and existing log sources. Continuously tune detections to reduce false positives, improve detection fidelity, and expand detection coverage across the environment. Develop security monitoring and detection content for AWS services, Kubernetes, microservices, Linux, macOS, databases, web applications, firewalls, and other enterprise technologies by leveraging the MIT
Presenting technical findings and recommendations to improve customers’ cybersecurity posture and performing threat intelligence knowledge transfer to prepare customers to defend against today’s threat landscape for and assisting in the development of production threat hunting tools, automations, and new capabilities.
Recommendation Engine: Partner with engineering to turn a diagnosis into action. Surface a suggested code fix. Confirm whether the customer’s logging can even detect the issue. Deliver a ready-to-use detection rule (e.g., Splunk) and a threat hunting query to check for past abuse. Cross-Functional Intelligence: Work closely with our Agentic Products PM team. Feed new attack vectors and data sources back into agent training. Help our agents learn to “look for the new thing.”
+17 more signals