Description

Staff XDR Detection Engineer

< View All Jobs

Location: Bengaluru, Karnataka, India

Department: Research & Development

Region: Asia, Pacific & Japan

About Us:

SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the network at machine speed – to defeat every attack, at every stage of the threat lifecycle. 

We are a values-driven team where names are known, results are rewarded, and friendships are formed. Trust, accountability, relentlessness, ingenuity, and OneSentinel define the pillars of our collaborative and unified global culture. We're looking for people that will drive team success and collaboration across SentinelOne. If you’re enthusiastic about innovative approaches to problem-solving, we would love to speak with you about joining our team!

What are we looking for?

We are seeking highly motivated individuals to join our XDR Default Rules Team. The ideal candidates will have a strong background in cybersecurity, with a focus on rule development for SIEM, EDR, XDR or similar platforms. We are looking for team players, adept at crafting precise and effective detection rules, and committed to staying at the forefront of cybersecurity advancements. If you are passionate about contributing to innovative cybersecurity solutions, come join us and be part of our dynamic team at SentinelOne.

What will you do?

As an XDR Detection Engineer, you will play a key role in crafting, owning, and packaging default rules for our XDR platform. Your responsibilities will include creating rules that correlate detections across third-party sources and time, performing false positive analysis, and actively contributing to the ongoing enhancement of our detection capabilities.

You will be responsible for the following:

  • Collaborate with team members to develop and implement default rules for the XDR platform.
  • Work on correlating detection events across diverse third-party sources and over time to enhance the effectiveness of detection rules.
  • Rigorously analyze and assess false positives associated with the rules you create.
  • Contribute to the optimization of rules to minimize false positives and enhance detection accuracy.
  • Collaborate with the team to optimize existing default rules for superior detection capabilities.
  • Stay informed about emerging threats, industry trends, and new technologies to continuously improve rule efficacy.
  • Follow good detection engineering practies the default rules you develop, including logic, descriptions and other metadata, tests, and more. 

 

What experience or knowledge should you bring?

  • Experience writing behavioral detection rules for SIEM, EDR, XDR, or other similar platforms. Experience writing YARA or other types of static detections is a nice to have.
  • Familiarity with building detections across the MITRE ATT&CK Matrix.
  • Proficiency in scripting and programming languages such as Python.
  • Familiarity with Detection Engineering processes including prioritizing a backlog for research and development, writing unit and integration tests, and with CI/CD technologies such as Jenkins. 
  • Experience building and maintaining detections for a cybersecurity software product is a nice to have, as is experience working in a SOC or other environment where detection products were used and alerts triaged.
  • Strong analytical and problem-solving skills, with an understanding of false positive analysis.
  • Knowledge of cybersecurity frameworks, threat intelligence, and industry best practices.
  • Excellent communication and collaboration skills within a team-oriented environment.

Why us?

You will be joining a cutting-edge company, where you will tackle extraordinary challenges and work with the very best in the industry along with competitive compensation. 

  • Flexible working hours and hybrid/remote work model.
  • Flexible Time Off.
  • Flexible Paid Sick Days.
  • Global gender-neutral Parental Leave (16 weeks, beyond the leave provided by the local laws) 
  • Generous employee stock plan in the form of RSUs (restricted stock units)
  • On top of RSUs, you can benefit from our attractive ESPP (employee stock purchase plan)
  • Gym membership/sports gears by Cultfit.
  • Wellness Coach app, with 3,000+ on-demand sessions, daily interactive classes, audiobooks, and unlimited private coaching. 
  • Private medical insurance plan for you and your family.
  • Life Insurance covered by S1 (for employees)
  • Telemedical app consultation (Practo)
  • Global Employee Assistance Program (confidential counseling related to both personal and work life matters)
  • High-end MacBook or Windows laptop.
  • Home-office-setup allowances (one time) and maintenance allowance. 
  • Internet allowances.
  • Provident Fund and Gratuity (as per govt clause)
  • NPS contribution (Employee contribution)
  • Half yearly bonus program depending on the individual and company performance.
  • Above standard referral bonus as per policy.
  • Udemy Business platform for Hard/Soft skills Training & Support for your further educational activities/trainings
  • Sodexo food coupons.

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles. 

Key Skills
Education

Any Graduate