Secure your enterprise with the autonomous cybersecurity platform. Endpoint. Cloud. Identity. XDR. Now.
Senior Detection Engineer - Windows, Identity Security
Location
Poland
Posted
9 hours ago
Salary
0
Seniority
Senior
Job Description
Senior Detection Engineer - Windows, Identity Security
SentinelOne
Role Description As a Senior Windows Identity Detection Engineer, you will research and detect emerging identity threats by developing behavior-based detection methods. You’ll build tools and PoCs to identify and prevent attacks such as Pass-the-Hash, Silver Ticket, and MFA bypass. Your work will directly strengthen the security of millions of Windows endpoints protected by the platform. In this role, you’ll have a unique opportunity to expand your skillset beyond just Windows security, and to not only contribute, but to significantly influence the buildout of a new side of our business - Identity security from the ground up! What will you do? - Detect the newest identity threats with end-to-end responsibility for behavior-based detection capabilities. - Research attack techniques and design new methods to detect or prevent those attacks. - Implement detection methods in the product (SW development in C++23 and scripting in Lua). - Develop and use internal research tools and PoCs to discover new ways to detect/prevent identity-based attacks. - Enhance the security of dozens of millions of Windows endpoints protected by the platform. Working setup - Flexible working hours; this is a 100% remote role on full-time permanent employment (UoP) based within Poland. - Optional membership in major coworking chains. - Consideration for candidates already eligible to work in the EU at the time of applying. - Relocation assistance available for those willing to relocate to the Czech Republic, provided they are eligible to work in the EU at the time of applying. Qualifications - 3+ years of experience in malware analysis (statically and dynamically). - 3+ years of experience with C++; knowledge of Lua or similar scripting language is an advantage. - Excellent understanding of Windows Internals (Process and Threads, Virtual Memory, etc.). - Experience with analysis tools such as IDA, WinDBG, SysInternals, etc. - Experience with identity-based attacks (Pass the Hash, Silver Ticket, MFA bypass) is a big plus. - Kernel development experience and/or understanding of existing AVs internals is an advantage. Benefits - Equity & Rewards: Restricted Stock Units (RSUs), Employee Stock Purchase Plan (ESPP). - Time Off & Wellbeing: Competitive leave benefits, gender-neutral parental leave. - Insurance & Financial Security: Medical and insurance benefits, pension scheme, Employee Assistance Program (EAP). - Work Perks & Flexibility: Global home office allowance, mobile phone allowance. - Wellness & Lifestyle: Wellness benefit.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Role Description You will own the Node.js Proactive Defense initiative — a new runtime security layer for Imunify360 that brings the same in-process protection model we already ship for PHP into the Node.js ecosystem. Today, hosting providers running multi-tenant Node.js workloads have no equivalent of mod_security + PHP Proactive Defense: malicious code, supply-chain payloads, and post-exploitation behavior execute inside the Node.js process with full privileges of the tenant. Your job is to close that gap. Concretely, You Will: - Design and ship a Node.js runtime agent that hooks into the V8/Node lifecycle to trace and block malicious behavior patterns (child_process spawn chains, eval / Function constructors, prototype pollution exploitation, unsafe deserialization, SSRF, path traversal, fs writes to sensitive locations, malicious require() / dynamic import chains, supply-chain poisoning at load time). - Define the detection model: which behaviors are policy-blockable by default, which are signal-only, and how rules are authored, distributed, and versioned alongside our existing Proactive Defense rule pipeline. - Integrate the agent with the rest of the on-host Imunify security stack so that Node.js detections, blocks, and incidents flow into the same telemetry pipeline, the same backend event store, and the same admin UI as our other layers (WAF, host-IDS, brute-force protection, malware scanner, patch management). - Make it production-safe on shared hosting: low overhead, tenant-isolated, compatible with CageFS / LVE, and resilient to hostile tenants who will try to disable or evade the agent. - Build the pipeline that turns CVE write-ups and threat-intel feeds into shipped detections. - Own the closed feedback loop from production blocks (true positives, false positives, evasions) back into the next generation of rules. This is a green-field, security-engineering-led role with direct product impact: the detections you write will run on hundreds of thousands of servers. Qualifications - Security engineer mindset: thinks in attack surfaces, exploit primitives, and defense-in-depth - not just in OWASP checklists. - Runtime/exploitation knowledge across languages: prototype pollution, deserialization, command injection, SSRF, path traversal, supply-chain poisoning. - Systems-level development: Linux daemons, systemd, privileged processes, IPC, namespaces/cgroups, file-descriptor and signal hygiene. - Low-level / instrumentation instinct: has hooked, traced, or intercepted something in production. Requirements - Shared-hosting / multi-tenant Linux experience: LVE, CageFS, control-panel ecosystems, or analogous tenant-isolation work. - Comfort working from a CVEs and threat-intel feed as primary product input. Benefits - A focus on professional development. - Interesting and challenging projects. - Fully remote work with flexible working hours, that allows you to schedule your day and work from any location worldwide. - Paid 24 days of vacation per year, 10 days of national holidays, and unlimited sick leaves. - Compensation for private medical insurance. - Co-working and gym/sports reimbursement. - Budget for education. - The opportunity to receive a reward for the most innovative idea that the company can patent.
Security Engineer
Aily LabsAt Aily Labs, we're building the AI operating system for business decisions. Our platform empowers organizations to make faster, smarter, and more consistent decisions by combining cutting-edge AI with deep business context. We work with leading enterprises across industries to transform how decisions are made — from strategy to execution. We're growing fast, and we're looking for exceptional people who want to shape the future of AI-driven decision-making.
Role Description Join our Security Engineering team as a Security Engineer who builds, not just operates. You will design and build security systems that protect our AI-driven platform at scale—whether that means securing cloud infrastructure and data pipelines, embedding security into our AI-powered products, engineering the detection and automation capabilities that keep us ahead of threats, or protecting corporate infrastructure and ensuring secure, well-architected business systems. You will own your work end-to-end and grow into one of our four specialization tracks as the team and your profile develop together. As a Security Engineer at Aily, you are a software engineer with deep security expertise. We are not looking for people who configure existing tools; we need engineers who write production-quality code to solve hard security problems in an AI-first company. You will face problems of the AI age: - Securing complex data flows across distributed systems - Protecting AI models and training pipelines - Building detection logic against real threats - Designing products that handle highly regulated data safely You will own projects from design through deployment and work closely with Engineering, Data Science, Platform, and Product teams. Where You’ll Specialize Our Security Engineering team operates across four tracks. You’ll share your preference during the process; we’ll confirm fit and align on where you’ll have the most impact: - Platform Security - Build the security infrastructure that protects Aily’s cloud platform, AI pipelines, and data ecosystem. - Design and build security automation systems and platforms — from control monitoring to advanced threat detection capabilities or agentic red teaming. - Secure complex data flows, data lakes, and AI training pipelines; implement DLP strategies at scale. - Protect AI models from adversarial attacks, data poisoning, and unauthorized access. - Implement cloud security controls for AWS environments and codify security policies through Infrastructure as Code. - Product Security - Embed security into our AI-powered products from the start, working closely with Product and R&D teams. - Design security architectures for AI/ML systems handling regulated data. - Conduct threat models and security architecture reviews across all engineering teams. - Design authentication and authorization architectures (SSO, OAuth/OIDC, RBAC/ABAC) and review third-party integrations. - Ensure GDPR/CCPA/EU AI Act compliance and integrate SAST/DAST into CI/CD pipelines. - Security Operations - Write production-quality code to build the detection logic and agentic observability platform that keeps Aily ahead of threats. - Design detection strategies against real attacker TTPs — from signal engineering to response workflows. - Build and operate an AI-native, agentic Security & Governance Observability Platform with autonomous agents that ingest telemetry, correlate signals, and execute responses. - Build data pipelines for security telemetry at scale and design intelligent automation that eliminates repetitive work. - Design incident response playbooks and automated remediation workflows across endpoint, cloud, and identity domains. - Corporate Security - Protect corporate infrastructure, ensure secure and well-architected business systems, and govern company-wide AI usage and agentic tooling. - Design and implement security controls for corporate infrastructure — MDM, identity management, endpoint security, and access control architectures. - Build security automation and tooling for compliance and policy enforcement across corporate systems. - Define and enforce policies for company-wide AI usage and agentic tooling — ensuring safe adoption, data boundaries, and governance guardrails. - Review and validate architectural decisions for business systems (HRIS, CRM, Finance, Legal, BI) from Security and Data Architecture perspectives. - Provide Enterprise Architecture governance — ensuring business systems meet security and architectural standards through review, patterns, and guidance. Qualifications - Software engineer who writes production-quality code to solve security problems — not just configure tools. - Strong systems thinking and ability to design at scale. - Cloud security experience (we use AWS) — Kubernetes, containers, cloud-native architectures. - AI-first mindset — you use AI tools daily and thrive in an AI-native environment. - Offensive security or red teaming background. - Clear communicator across technical and non-technical teams. Requirements - Platform Security: - DLP in production environments. - Securing data-intensive systems (data lakes, analytics, AI pipelines). - Building security platforms or governance tooling from scratch. - Product Security: - Privacy engineering (GDPR/CCPA). - Security architecture for AI/ML and regulated data. - Threat modeling · IAM (SSO, OAuth/OIDC, RBAC/ABAC). - Regulatory compliance (EU AI Act, HIPAA, SOX). - Security Operations: - Detection engineering against real TTPs. - Incident response or threat hunting. - Working with large-scale security telemetry. - Corporate Security: - Corporate Security systems (MDM, identity management, endpoint security). - Identity and access management (Okta, Entra ID, Azure AD). - Enterprise architecture review and governance. - AI usage governance and agentic tooling security. Benefits - Build security from the ground up at an AI-first company — our security platform is greenfield, not legacy. - Work where using AI to solve problems is expected and encouraged, not discouraged — we are building one of the most advanced agentic security capabilities in the industry. - Own your work end-to-end with real impact across the company, not just a narrow slice of a large team. - Enjoy the flexibility of remote work, continuous growth, and dedicated training resources to support your professional development.
Manager of Security Intelligence
Edison InternationalEdison International has been a leader in electricity services since it was established in southern California in 1886. Today, through its subsidiaries, the com
Manager of Security Intelligence Location: Irwindale United States Job Family: Safety, Security & Business Resiliency Pay: $129,200 – $193,700 Job Description: Join the Clean Energy Revolution Become a Manager of Security Intelligence at Southern California Edison (SCE) and build a better tomorrow. In this job, you'll be an integral part of protecting SCE's workforce, customers, facilities, and infrastructure from threats, attacks, disruptions, intrusions, theft, and property damage. As the Manager of Security Intelligence, you will be a working member of the Security Operations & Intelligence team overseeing a small team of analysts. Your work will help power our planet, reduce carbon emissions and create cleaner air for everyone. Are you ready to take on the challenge to help us build the future? Responsibilities - Leads the coordination of intelligence collection, assessments, and shares the results with appropriate business unit leadership to ensure a holistic view of security risk management and regulatory compliance is established. - Manages the daily monitoring of threats to the business including activist organizations, criminal activities, regional and world events that may impact SCE operations. - Develops Intel Team policies and procedures to meet the varied needs of the organization, ensures resources are properly utilized and prioritized, and provides leadership, guidance, and training to team members to meet operational requirements. - Leads and oversees the distribution of work assignments based on workload, skill sets, risk priorities and the performance of vendors and internal teams. - Develops intel security risk strategies and provides guidance to senior security management in operational security and risk-related matters. - Provides leadership and direction during internal and external security risk and regulatory compliance audits, inspections, and surveillances. - Establishes programs and procedures to enforce the quality and reliability of our intelligence and security posture. - Builds external partnerships and internal collaborations for information sharing that is essential for situational awareness in the protection of SCE employees, assets and customers. - A material job duty of all positions within the Company is ensuring the protection of all its physical, financial and cybersecurity assets, and properly accessing and managing private customer data, proprietary information, confidential medical records, and other types of highly sensitive information and data with the highest standards of conduct and integrity. Minimum Qualifications - Five or more years combined experience performing or leading intelligence gathering in a corporate security, military, law enforcement environment, or other US government environment. - Experience in developing intel security risk strategies. - Three or more years of experience in a position where regular reports are delivered in written and oral presentation form to large groups and/or senior leaders. Preferred Qualifications - Bachelor's degree in business administration, criminal justice, communications or an equivalent of education, training, and experience. - Graduate degree in business administration, intelligence or a related field. - ASIS CPP or PSP certification. Intelligence certification. Additional Information - This position's work mode is hybrid. The employee will report to an SCE facility for a set number of days with the option to work remotely on the remaining days. Unless otherwise noted, employees are required to work and reside in the state of California. Further details of this work mode will be discussed at the interview stage. The work mode can be changed based on business needs. - Visit our Candidate Resource page to get meaningful information related to benefits, perks, resources, testing information, hiring process, and more! - Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. - The primary work location for this position is Irwindale, CA. However, the successful candidate may also be asked to work for an extended amount of time at (alternate work location). - Position will require up to 20% local traveling and being out in the field throughout the SCE service territory. - This position has been identified as a NERC/CIP impacted position - Prior to being hired, the successful candidate must pass a Personnel Risk Assessment (PRA) or Background Investigation. Once hired, the candidate must complete specified training prior to gaining un-escorted access to assigned work location and performing necessary job duties. - Relocation may apply to this position. About Southern California Edison The people at SCE don't just keep the lights on. Our mission is so much bigger. We're fueling the kind of innovation that's changing an entire industry, and quite possibly the planet. Join us and create a future with cleaner energy, while providing our customers with the safety and reliability they demand. At SCE, you'll have a chance to grow personally and professionally, making a real impact in Southern California and around the world.
Cybersecurity Engineer Senior
Huntington National BankSine 1866, Huntington National Bank has served midwestern communities with banking and financial services for consumers and businesses of all sizes. The regiona
Title: Cybersecurity Engineer Senior Location: Atlanta, GA 901 South Mopac, Bldg 2, Suites 355/360 Austin, TX 500 Corporate Pkwy Hoover, AL 222 North LaSalle St Chicago, IL 7 Easton Oval Columbus, OH 7906 North Sam Houston Parkway West Houston, TX 2025 Woodward Ave Detroit, MI 11100 Wayzata Blvd Minnetonka, MN 101 South Tryon Street Charlotte, NC 12750 Merit Dr. Dallas, TX Reference Number:R0072213 Job Description: Description This position is an onsite position and is available to be filled at any Huntington Corporate office location (see location options on posting) Summary: The Cybersecurity Engineer Senior will focus internet proxy and internet filtering. Will work with other security teams and users as needed to support internet access functionality. This will include user support, configuration maintenance and updates, and planning/implementing new features/tools as needed. Duties & Responsibilities: - Supports and manages internet proxy and internet filtering duties. - Reviews completion and implementation of system additions and/or enhancements and makes recommendations to management and/or business partners. - Integrates existing automation, application and monitoring systems. - Works with the Cybersecurity Operations Center to collaborate and engage on potential use cases for Security Automation. - Other duties as assigned. Basic Qualifications: - 3+ years Experience in Internet Proxy/Internet Filtering tools. - 1-3+ years experience in data reporting/analytics. - Associate's Degree or 4+ additional years of equivalent experience. Preferred Qualifications: - Knowledge of remote browser isolation and/or enterprise browsers. - Knowledge of network communications and protocols. - Knowledge in SIEM and/or Orchestration and Automation tool sets. - Effective troubleshooting and problem-solving skills. - Strong written and verbal communication skills. - Proven experience building effective working relationships with cross-functional partners. Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay) Yes Workplace Type: Office Our Approach to Office Workplace Type Certain positions outside our branch network may be eligible for a flexible work arrangement. We're combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team. Huntington will not sponsor applicants for this position for immigration benefits, including but not limited to assisting with obtaining work permission for F-1 students, H-1B professionals, O-1 workers, TN workers, E-3 workers, among other immigration statuses. Applicants must be currently authorized to work in the United States on a full-time basis. Compensation Range: $57,000 - $113,000 Annual Salary The compensation range represents the anticipated low and high end of the base compensation range for this position. Actual compensation will vary based on various factors including but not limited to location, experience, and education. Colleagues in this position are also eligible to participate in an applicable incentive compensation plan. In addition, Huntington provides a variety of benefits to colleagues, including health insurance coverage, wellness program, life and disability insurance, retirement savings plan, paid leave programs, paid holidays and paid time off (PTO). Huntington is an Equal Opportunity Employer.



