Barracuda Networks logo
Barracuda NetworksPosted 1 week ago

Cybersecurity Engineer

$114,000–$152,000 year

RemoteUnited States

Full TimeLarge

Job Summary

Research emerging threats, vulnerabilities, and adversary tradecraft to translate attacker behaviors into actionable detection and defensive capabilities. Conduct controlled adversary simulations and reproduce TTPs to validate detection effectiveness and identify gaps in coverage. Collaborate with Threat Intelligence, Security Operations, Incident Response, and Product teams to improve visibility into attack paths and strengthen the feedback loop across security functions. Mentor team members and communicate complex technical findings to both technical and non-technical audiences. This role sits at the intersection of offensive security, detection engineering, and threat intelligence, focusing on proving that defenses work against realistic scenarios.

Required Qualifications

  • 5+ years of hands-on experience in offensive security, threat research, detection engineering, threat intelligence, incident response, or a closely related discipline
  • Strong understanding of modern attacker tradecraft and the ability to analyze how real-world adversaries operate
  • Demonstrated experience researching vulnerabilities, exploits, malware, or emerging attack techniques
  • Experience translating adversary behaviors and TTPs into detection opportunities or defensive requirements
  • Hands-on experience with adversary emulation, red teaming, penetration testing, or attack simulation
  • Experience developing or validating detections using SIEM, EDR, XDR, network, cloud, identity, or other security telemetry
  • Strong understanding of the MITRE ATT&CK framework and how to map adversary behavior to observable activity and defensive coverage
  • Ability to analyze complex attack chains and determine where meaningful detection and prevention opportunities exist
  • Strong scripting or programming skills in languages such as Python, PowerShell, Bash, or similar
  • Hands-on experience with Windows, Unix, and Linux operating systems
  • Understanding of network protocols and enterprise security architecture
  • Experience working with cloud environments such as AWS or Azure
  • Ability to independently research unfamiliar technologies, vulnerabilities, and attack techniques and quickly develop a working technical understanding
  • Strong written and verbal communication skills, with the ability to explain technical attack behavior and security risk clearly
  • Relevant certifications such as OSCP, OSEP, OSCE, GXPN, GCIA, GCIH, CEH, or equivalent practical experience

Desired Qualifications

  • Experience building adversary emulation tooling or automated attack simulations
  • Experience developing detection analytics, correlation rules, behavioral detections, or detection-as-code
  • Experience with EDR/XDR, SIEM, cloud security, identity security, or network detection technologies
  • Experience analyzing public vulnerability disclosures and determining practical exploitability and detection opportunities
  • Experience conducting Purple Team or Attack & Defend exercises
  • Experience measuring detection coverage and identifying missed adversary TTPs
  • Experience with threat hunting and hypothesis-driven investigations
  • Experience researching novel exploitation techniques or emerging attacker tradecraft
  • Experience contributing to open-source security research, vulnerability research, or offensive security tooling

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce