SenseOn makes advanced cybersecurity quickly accessible for organisations of all sizes. Our mission is your mission.
Security Engineer
Location
Argentina
Posted
105 days ago
Salary
0
Seniority
Senior
Job Description
Security Engineer
SenseOn
• Author and maintain detection rules across SenseOn's dual-engine architecture: • Real-time streaming detections evaluated in milliseconds, written as YAML compiled to binary rulesets • Batch behavioral detections backed by parameterised ClickHouse SQL, running on a seconds-to-minutes cadence • Write aggregations and materialised views in ClickHouse that power statistical anomaly baselines • Build and extend our hunting query library. MITRE-mapped ClickHouse queries that analysts use daily for threat hunting • Map every rule precisely to MITRE ATT&CK techniques and tactics, including subtechnique granularity • Instrument your own rules: measure false positive rates, define confidence scores, build test datasets, and own the quality of what ships • Tune detections against real-world telemetry. Understanding why a rule fires is as important as making it fire • Extend our existing LLM driven rule writing engine to have much wider coverage • Design and build pipelines where LLMs can propose detection rules from threat intelligence, CVE disclosures, or analyst hunt findings, with structured output, YAML validation, and human-in-the-loop approval gates • Build feedback loops: when a detection fires or produces a false positive, that signal should flow back to improve future AI-generated rules • Define the prompt engineering and evaluation harness for detection generation. Pass@k metrics, FP/TP scoring, MITRE alignment validation • Work with engineering to make the detection data model AI-legible: schemas, annotations, and context structures that LLMs can reason over reliably • Think about our hunting interface: how does an analyst describe a threat in natural language and get a validated ClickHouse query back?
Job Requirements
- 3+ years writing detection content: SIEM rules, EDR detections, YARA, Sigma, or equivalent; you understand the craft of reducing noise without missing signals
- Strong working knowledge of MITRE ATT&CK: Not just citing technique IDs but reasoning about adversary tradecraft and tactic chaining
- SQL proficiency: You write analytical queries comfortably and understand how query performance affects detection latency at scale
- Hands-on experience with LLMs in a production or engineering context: You've written prompts, evaluated outputs, and built something that used an LLM API (not just chatted with one)
- Python fluency: Enough to read, write, and debug the kind of Python that runs detection pipelines, builds API endpoints, and processes security telemetry
- Ability to evaluate AI-generated output critically: You understand where LLMs hallucinate in security contexts and how to build guardrails
- Clear, precise written communication in English: Detection rules, prompt templates, and eval criteria all live in text
- Strong Advantage
- Experience with ClickHouse or other columnar / OLAP databases
- Familiarity with Protocol Buffers or binary serialisation formats
- Background in threat hunting: Building hypotheses, writing queries, and operationalising findings as detections
- Experience designing or contributing to AI evaluation frameworks (eval harnesses, golden datasets, pass@k scoring)
- Exposure to network or endpoint telemetry at volume: DNS, NTLM, Kerberos, process execution, network flows
- Prior work at a security vendor, MDR, or SOC where detection quality had direct customer impact
Benefits
- Competitive salary
- Unlimited holiday allowance
- Bi-annual career progression review
- Learning and development investment (certs, conferences, etc)
- Work MacBook
- Belong at SenseOn:**
- At SenseOn, we define Talent as employees who are ❤️ customer obsessed, 🌟 pursuing excellence. They are 🦁 courageous, 🦸♀️🦸🏽♂️ good people, doing good things, powering our 🚀 rocketship. If this resonates with you, then you will always belong. Nothing else matters. We are an Equal Opportunity Employer and do not discriminate against any qualified employee or applicant. Difference is what makes us stronger.
- Prior to the next stage in our recruitment process, please don’t hesitate to confidentially let us know if you require any support to allow you to fully participate in our process
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Develop and implement the organization's information security strategy. • Provide regular security updates to the CIO, other executives, and the board of directors, including presentations on security matters. • Represent the organization in security-related matters with external parties, including vendors and auditors. • Work closely with the CIO and operate as a member of the DevOps team to emphasize and implement security initiatives. • Conduct regular risk assessments and vulnerability scans using tools like Rapid7 IVM and internal tracking systems. • Oversee the development and implementation of incident response plans and conduct tabletop exercises with DevOps team members. • Ensure compliance with relevant regulations and standards, including HITRUST, NIST, DirectTrust, HIPAA, SOC 2 (Type II), ISO. • Manage internal and external security audits, including evidence collection and preparation. • Develop, review, and update information security policies and procedures, including the Vulnerability and Patch Management Procedure and Data Center Access Procedure. • Participate in the day-to-day operations of the security team and manage security tools and technologies, including Check Point, SentinelOne, and intrusion detection systems. • Lead and mentor the security team, reviewing tasks and responsibilities working closely with the DevOps team members. • Evaluate and manage security vendors, including VDA Labs, KnowBe4, and perform vendor audits.
Sales Development Representative, Tech, SaaS, Cybersecurity
Hire Hangar GlobalOffshoring as a service. Hire the top 1% of flexible, global talent. $0 fees to get started.
• Execute outbound prospecting campaigns via phone, email, and LinkedIn • Qualify inbound and outbound leads to identify sales-ready opportunities • Educate prospects on Tech, SaaS, cybersecurity, FinTech, and AI solutions • Set qualified meetings and demos for Account Executives • Research target accounts and identify key stakeholders • Maintain accurate CRM records and pipeline activity
Director of Security and Facilities
Sigma Defense Systems LLCConnecting people, systems and data from space to operator for data superiority
• Provide expert recommendations, advice, and input during all phases of the project: Planning, Design, Initiation, Setup, and Accreditation to the SAF/AQ Special Security Officer (SSO)/DIA Accrediting Official (AO). • Provide expertise to the U.S. government throughout the construction process and ensure that all design reviews and final plans are done in accordance with the ICD-705, TEMPEST 1/13, DoD 5200 and other DoD/IC Directives and Guidelines to ensure a final accreditation secure area at construction completion. • Advise AO of any discrepancies, variances, contractor misconduct and other securing incidents and delays.
Lead Security Engineer
GoodRxGoodRx offers an online platform dedicated to transparent prescription pricing in the United States. The company's programs and mobile apps are used by more than 7 million individu
• Define and evolve the security architecture across cloud, application, and infrastructure domains. • Lead threat modeling and risk analysis for complex systems and new product initiatives. • Develop and guide implementation of secure design principles across engineering teams. • Evaluate emerging security technologies and recommend strategic adoption. • Perform enterprise-level risk assessments and translate findings into prioritized remediation roadmaps. • Define and improve security policies, standards, and control frameworks. • Drive alignment of security practices with regulatory and compliance requirements. • Provide executive-ready summaries of risk posture and mitigation strategy. • Lead complex security investigations and incident response efforts. • Conduct root cause analysis and implement systemic improvements to reduce future risk. • Develop and refine runbooks, playbooks, and response automation. • Act as an escalation point for high-impact security events. • Partner with engineering teams to integrate security into the SDLC. • Define standards for secure code reviews and static/dynamic analysis. • Improve automation for vulnerability scanning, detection, and remediation. • Guide cloud security best practices across AWS/GCP environments. • Act as a trusted advisor to engineering leadership and cross-functional partners. • Influence technical decisions that balance security, scalability, and delivery speed. • Foster strong relationships with vendors and external security partners. • Mentor and guide junior security engineers and engineers outside the security team.




