Flock - Senior Adversary Pursuit Engineer
Requirements
• Leadership & Management: • Mold the long-term threat hunting roadmap, including strategy, data ingestion requirements, and coverage metrics. • Help design, execute, and see complex threat hunting campaigns through to completion, taking ownership of specific threat verticals (e.g., cloud environments, specific APT groups). • Serve as a technical mentor for junior and mid-level engineers. Review their technical work, provide constructive feedback on methodologies, and elevate the team's overall technical baseline. • Technical Expertise: • Extensive technical expertise in performing DFIR and adversary threat hunts, across diverse environments (corporate systems, cloud - AWS/GCP/Azure, and operational technology networks). • Experience with performing DFIR on Android IoT devices. • Deep experience utilizing enterprise security tooling (SIEM, EDR, etc.) as well as developing proprietary tools/scripts to scale the team’s capabilities. • Experience utilizing sandboxing technology to aid in the analysis of suspicious binaries and scripts; hands-on reverse engineering experience a plus. • Hands on work with integrating security automation tools (Torq, Tines, SIEM native, etc.) and AI tooling (LLMs, agentic workflows) to accelerate security operations • Map findings to the MITRE ATT&CK framework to identify coverage gaps and improve detection posture. • Well versed in using cyber threat intelligence to update requirements, prioritize collection sources and integrate technical TTPs to inform and prioritize hunts. • Create and tune high-fidelity detection rules (e.g., Splunk SPL, YARA, Sigma) based on hunt findings to prevent future recurrence. • Assist with the development of technical table top exercises, ensuring scenario applicability to the organization’s risk profile and align to real world cyber events. • Collaborate with Cybersecurity, Engineering, and Product teams to help plan, and execute threat hunts, providing detailed findings and data backed recommendations for cybersecurity and architectural improvements. • Work closely with the Offensive Security team to help perform regular testing and validation of custom detection rules. • Serve as a Tier 3 escalation point for SOC analysts; perform deep-dive root cause analysis on complex security incidents. • Feeling uneasy that you haven’t ticked every box? That’s okay; we’ve felt that way too. Studies have shown women and minorities are less likely to apply unless they meet all qualifications. We encourage you to break the status quo and apply to roles that would make you excited to come to work every day. • 90 Days at Flock • 90 Days at Flock • We prescribe to 90 day plans and believe that good days lead to good weeks, which lead to good months. This serves as a preview of the 90 day plan you will receive if you were to be hired in this role at Flock. • The First 30 Days • The First 30 Days • Build a deep understanding of the company’s technology stack, threat landscape, and existing security operations and response practices • Establish strong partnerships with Engineering, Infrastructure, Product Security, and Offensive Security teams • The First 60 Days • The First 60 Days • Help identify areas of focus within Adversary Pursuit, aligned to risk tolerance and business priorities, to help with development of a long term roadmap • Assist with identifying opportunities to improve visibility (logs and intelligence) and detection capabilities • 90 Days & Beyond • 90 Days & Beyond • Help with building an organizational Cyber Threat Profile with prioritized threat actors and intelligence collection requirements and proactively identifying attacker TTPs • Develop a phased roadmap to mature Adversary Pursuit capabilities, including visibility and detection gap remediations and tooling improvements as well as plans for incorporation into regular exercises
Benefits
• In this role, you’ll receive a starting salary between $140,000 and $175,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in-depth with you during our first chat. • Location • We’re building the impossible, together. To drive innovation through in-person collaboration, we’re prioritizing candidates in our key hubs: Atlanta, Boston, Chicago, Denver, Los Angeles, New York City, San Francisco, and Austin. While we value the energy of our hub communities, we embrace remote work and welcome applications from exceptional talent across the United States. • 🌴Flexible PTO: We offer non-accrual PTO, plus 11 company holidays. • Flexible PTO • ⚕️Fully-paid health benefits plan for employees: including Medical, Dental, and Vision and an HSA match. • Fully-paid • plan for employees • 👪Family Leave: All employees receive 12 weeks of 100% paid parental leave. Birthing parents are eligible for an additional 6-8 weeks of physical recovery time. • Family Leave • 🍼Fertility & Family Benefits: We have partnered with Maven, a complete digital health benefit for starting and raising a family. Flock will provide a $50,000-lifetime maximum benefit related to eligible adoption, surrogacy, or fertility expenses. • 🧠Spring Health: Spring Health offers a variety of mental health benefits, including therapy, coaching, medication management, and digital tools, all tailored to each individual's needs. • Spring Health: • 💖Caregiver Support: We have partnered with Cariloop to provide our employees with caregiver support • Caregiver Support: • 💸Carta Tax Advisor: Employees receive 1:1 sessions with Equity Tax Advisors who can address individual grants, model tax scenarios, and answer general questions. • Carta Tax Advisor: • 💚ERGs: We want all employees to thrive and feel like they belong at Flock. We offer four ERGs today - Women of Flock, Flock Proud, LEOs and Melanin Motion. If you are interested in talking to a representative from one of these, please let your recruiter know. • ERGs: • 💻WFH Stipend: $150 per month to cover the costs of working from home. • 💻WFH Stipend: • 📚Productivity Stipend: $300 per year to use on Audible, Calm, Masterclass, Duolingo and so much more. • 📚Productivity Stipend: • 🏠Home Office Stipend: A one-time $750 to help you create your dream office. • 🏠Home Office Stipend: • If an offer is extended and accepted, this position requires the ability to obtain and maintain Criminal Justice Information Services (CJIS) certification as a condition of employment. Applicants must meet all FBI CJIS Security Policy requirements, including a fingerprint-based background check.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT