{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/telemetry-analysis"},"x-facet":{"type":"skill","slug":"telemetry-analysis","display":"Telemetry Analysis","count":3},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_c2aaf7ac-804"},"title":"Security Engineer - Threat Detection","description":"<p><strong>Job Description</strong></p>\n<p>You will design, build, and maintain detections that identify malicious activity across Stripe&#39;s infrastructure, applications, and cloud environments.</p>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Design, build, and tune high-fidelity detections across modern SIEM platforms, covering adversary TTPs across the full attack lifecycle</li>\n<li>Develop detection hypotheses by researching TTPs, identifying evidence sources, and determining detection opportunities across available telemetry</li>\n<li>Conduct hypothesis-driven threat hunts to identify malicious activity, uncover detection gaps, and validate security controls</li>\n<li>Perform malware analysis and reverse engineering to extract indicators and inform detection strategies</li>\n<li>Build network-based detections (flow, pcap, protocol analysis) and endpoint-based detections (event logs, EDR telemetry, memory/file artifacts) across Windows, Linux, and macOS</li>\n<li>Partner with Threat Intelligence to operationalize intel reports into detections, hunting leads, and enrichment logic</li>\n<li>Collaborate with IR, SOC, and offensive security teams to validate and refine detections based on real-world incidents and red team exercises</li>\n<li>Build data pipelines, automation, and tooling that enable detection-as-code practices and scalable deployment</li>\n<li>Map detection coverage to MITRE ATT&amp;CK, identifying and prioritizing gaps across key attack surfaces</li>\n<li>Lead projects, mentor teammates, and champion quality standards within the team</li>\n</ul>\n<p><strong>Requirements</strong></p>\n<ul>\n<li>5+ years of experience in detection engineering, threat hunting, or security operations</li>\n<li>Demonstrated experience writing detection logic in modern SIEM platforms (e.g., Splunk, Chronicle, Elastic, CrowdStrike NG-SIEM, Panther, Microsoft Sentinel)</li>\n<li>Strong understanding of adversary tradecraft across the attack lifecycle: initial access, privilege escalation, lateral movement, defense evasion, persistence, and exfiltration</li>\n<li>Ability to extract TTPs from threat intelligence reports and translate them into detection opportunities</li>\n<li>Experience developing network-based and endpoint-based detections across multiple OS platforms (Windows, Linux, macOS)</li>\n<li>Experience analyzing telemetry across endpoint, network, cloud (AWS/GCP/Azure), identity, and application log sources</li>\n<li>Proficiency in detection/query languages (SPL, KQL, EQL, YARA-L, SQL) and programming (Python or similar)</li>\n<li>Strong communication skills with the ability to document detection logic and explain findings to technical and non-technical audiences</li>\n<li>Adversarial mindset , understanding how attackers operate to build detections that catch real-world threats</li>\n</ul>\n<p><strong>Preferred Qualifications</strong></p>\n<ul>\n<li>Experience in detection engineering or threat hunting within fintech, financial services, or highly regulated environments</li>\n<li>Background in malware analysis, reverse engineering, or threat research</li>\n<li>Experience with purple team operations , collaborating with offensive security to validate detections</li>\n<li>Familiarity with big data platforms (Databricks, Trino, PySpark) for large-scale log analysis</li>\n<li>Proficiency with AI/LLM-assisted development tools (Claude Code, Cursor, GitHub Copilot) applied to detection workflows</li>\n<li>Interest in agentic automation , using LLMs to augment hunting, tuning, or triage</li>\n<li>Experience with detection validation tools (Atomic Red Team, ATT&amp;CK Evaluations)</li>\n<li>Contributions to open-source detection content, research, or conference presentations</li>\n<li>Relevant certifications such as HTB CDSA, GCIH, GCFA, GNFA, OSCP, TCM PMAT, or GREM</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_c2aaf7ac-804","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Stripe","sameAs":"https://stripe.com/","logo":"https://logos.yubhub.co/stripe.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/stripe/jobs/7827230","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["detection engineering","threat hunting","security operations","SIEM platforms","adversary tradecraft","network-based detections","endpoint-based detections","telemetry analysis","detection/query languages","programming","communication skills"],"x-skills-preferred":["fintech","financial services","malware analysis","reverse engineering","purple team operations","big data platforms","AI/LLM-assisted development tools","agentic automation","detection validation tools","open-source detection content","relevant certifications"],"datePosted":"2026-04-18T15:53:27.161Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Ireland"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"detection engineering, threat hunting, security operations, SIEM platforms, adversary tradecraft, network-based detections, endpoint-based detections, telemetry analysis, detection/query languages, programming, communication skills, fintech, financial services, malware analysis, reverse engineering, purple team operations, big data platforms, AI/LLM-assisted development tools, agentic automation, detection validation tools, open-source detection content, relevant certifications"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_a1ab2590-2b4"},"title":"Staff Security Engineer, Network Security","description":"<p>We are seeking a Staff Network Security Engineer to architect the defense of our global backbone, edge, and massive-scale GPU clusters. You will move beyond configuring firewalls to engineering security into the network fabric itself,utilizing telemetry, automation, and deep protocol analysis.</p>\n<p>As a Staff Network Security Engineer, you will:</p>\n<p>Unravel and tackle network security challenges at an exhilarating global scale. Collaborate with exceptional network architects and engineers building the backbone infrastructure for the AI revolution. Enjoy the freedom and support to experiment, innovate, and significantly shape our approach to securing the underlay and overlay of our cloud.</p>\n<p>In this role, you will: Conducting architecture reviews, protocol analysis, and design assessments to proactively identify and fix vulnerabilities in our backbone and data center fabrics. Developing robust, repeatable frameworks for network security automation (CoPP, ACL generation, Route Filtering) that make it easy for teams to build securely from day one. Collaborating closely with Network Engineering teams to integrate security checks and validation seamlessly into their CI/CD and config-push pipelines. Crafting clear, practical security guidance and documentation that empowers engineers to deploy secure routing policies and topologies. Actively participating in architectural discussions regarding peering, transit, and traffic engineering, providing insightful security recommendations. Occasionally, &#39;drawing the owl&#39; - figuring out innovative solutions for securing massive throughput environments while navigating ambiguous situations.</p>\n<p>You will be working with a talented team of network engineers, security experts, and AI researchers to build and deploy a highly scalable and secure cloud infrastructure.</p>\n<p>If you are passionate about network security, cloud computing, and AI, and enjoy working in a fast-paced, dynamic environment, we encourage you to apply for this exciting opportunity.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_a1ab2590-2b4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"CoreWeave","sameAs":"https://www.coreweave.com","logo":"https://logos.yubhub.co/coreweave.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coreweave/jobs/4620164006","x-work-arrangement":"hybrid","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$188,000 to $275,000","x-skills-required":["core network protocols (BGP, OSPF/IS-IS, TCP/IP)","deep knowledge of how they function at the packet level","network automation or security tooling in Go, Python, or similar modern languages","collaborating with network architects to implement secure designs in multi-vendor environments","Linux networking internals, control plane protection, and managing infrastructure as code"],"x-skills-preferred":["hyperscale network architectures (CLOS fabrics, MPLS/EVPN, VXLAN)","hardware-level networking security (SmartNICs/DPUs, connectX)","flow-based telemetry analysis","internet routing security standards (RPKI, MANRS)","advanced DDoS mitigation strategies at the network layer","Infiniband and RoCE"],"datePosted":"2026-04-18T15:52:43.431Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"core network protocols (BGP, OSPF/IS-IS, TCP/IP), deep knowledge of how they function at the packet level, network automation or security tooling in Go, Python, or similar modern languages, collaborating with network architects to implement secure designs in multi-vendor environments, Linux networking internals, control plane protection, and managing infrastructure as code, hyperscale network architectures (CLOS fabrics, MPLS/EVPN, VXLAN), hardware-level networking security (SmartNICs/DPUs, connectX), flow-based telemetry analysis, internet routing security standards (RPKI, MANRS), advanced DDoS mitigation strategies at the network layer, Infiniband and RoCE","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":188000,"maxValue":275000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_4474c998-9c7"},"title":"Cyber Security Engineer","description":"<p><strong>Cyber Security Engineer</strong></p>\n<p><strong>What we&#39;re all about</strong></p>\n<p>At Quantexa, we&#39;re a team of innovators and problem solvers who are passionate about creating real change for our clients and their industries. We&#39;re driven by a desire to do things better than the last time, and we&#39;re always looking for talented individuals to join our team.</p>\n<p><strong>The opportunity</strong></p>\n<p>We&#39;re seeking a highly skilled Cyber Security Engineer to join our Security Operations team. As a Cyber Security Engineer, you will play a key part in protecting Quantexa&#39;s systems and data from cyber threats. You will be responsible for the day-to-day operation, optimisation, and monitoring of core security platforms, with a particular focus on Zscaler, Cloud monitoring through Wiz, and Endpoint Detection and Response through CrowdStrike.</p>\n<p><strong>Responsibilities</strong></p>\n<p><strong>Wiz (Cloud Security Posture Management)</strong></p>\n<ul>\n<li>Monitor and triage Wiz findings daily, validating alerts and determining operational impact.</li>\n<li>Perform tuning and threat hunting within Wiz and other tooling.</li>\n<li>Identify misconfigurations, excessive permissions, and exposed assets, escalating where required.</li>\n<li>Track remediation progress with engineering owners and ensure closure of high-priority issues.</li>\n</ul>\n<p><strong>Zscaler (Web Security Tunnel 2.0)</strong></p>\n<ul>\n<li>Review and triage Zscaler alerts and policy violations, following documented response procedures.</li>\n<li>Investigate suspicious traffic, access attempts, and user activity to determine legitimacy and risk.</li>\n<li>Support enforcement actions by validating policy alignment and working with IT and Cloud teams to remediate issues.</li>\n<li>Monitor coverage and configuration across users and locations, identifying gaps or misconfigurations.</li>\n<li>Support policy tuning by analysing false positives and recommending rule or policy adjustments.</li>\n<li>Contribute to playbook development, operational maturity, and ongoing service readiness.</li>\n</ul>\n<p><strong>CrowdStrike (Endpoint Detection and Response)</strong></p>\n<ul>\n<li>Review and triage endpoint detections, applying documented response steps.</li>\n<li>Execute containment actions, including network isolation and sensor troubleshooting.</li>\n<li>Validate full sensor coverage across the estate and address gaps in coordination with IT.</li>\n<li>Support tuning activities by analysing false positives and proposing rule refinements.</li>\n<li>Contribute to playbook improvements and operational readiness tasks.</li>\n</ul>\n<p><strong>Security Operations</strong></p>\n<ul>\n<li>Conduct initial investigation of security incidents, collect evidence, and escalate based on severity with a keen eye on the quality of the output.</li>\n<li>Perform daily review of alerts across our SIEM, Wiz, CrowdStrike, and other platforms.</li>\n<li>Validate vulnerabilities and configuration weaknesses raised by scanning tools.</li>\n<li>Ability to interpret and operationalise threat intelligence, understand how it informs detection, prioritisation, and response activities, and clearly communicate technical threat intelligence to non-technical stakeholders.</li>\n<li>Support cloud security controls, identity hygiene checks, and network policy reviews.</li>\n<li>Contribute to the ongoing maturity and documentation of operational processes.</li>\n</ul>\n<p><strong>Collaboration and Ways of Working</strong></p>\n<ul>\n<li>Act as a trusted operational partner to the Cyber Security Manager and the wider Information Security team, providing proactive support and consistent engagement.</li>\n<li>Partner closely with DevOps, IT, and Engineering teams to drive timely and effective remediation actions.</li>\n<li>Deliver clear and concise updates on incidents and operational activities proactively, without the need for prompting.</li>\n<li>Actively participate in team stand ups, contributing constructively to continuous improvement and operational maturity.</li>\n<li>Support senior engineers with platform enhancements, integrations, and controlled change activities.</li>\n</ul>\n<p><strong>What you&#39;ll bring</strong></p>\n<ul>\n<li>Demonstrated hands-on experience with security operations, incident triage, or vulnerability management.</li>\n<li>Familiarity with EDR platforms (ideally CrowdStrike) and security telemetry analysis.</li>\n<li>Knowledge of cloud environments, particularly Azure including Entra and Conditional Access, and a good understanding of cloud security concepts.</li>\n<li>Ability to understand alert context, assess impact, and follow structured response processes.</li>\n<li>Strong attention to detail, disciplined documentation, and good communication skills.</li>\n</ul>\n<p><strong>Benefits</strong></p>\n<ul>\n<li>Competitive salary</li>\n<li>Company bonus</li>\n<li>Hybrid workplace &amp; free access to global WeWork locations &amp; events</li>\n<li>Pension Scheme with a company contribution of 6% (if you contribute 4% or more)</li>\n<li>25 days annual leave</li>\n<li>Flexible working hours</li>\n<li>Professional development opportunities</li>\n<li>Access to a range of employee benefits, including health insurance, gym membership, and more</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_4474c998-9c7","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Quantexa","sameAs":"https://jobs.workable.com","logo":"https://logos.yubhub.co/view.com.png"},"x-apply-url":"https://jobs.workable.com/view/5jNMqMFg7cJnLPEDaozihW/hybrid-cyber-security-engineer-in-london-at-quantexa","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Cloud Security Posture Management","Endpoint Detection and Response","Web Security","Security Operations","Threat Intelligence","Cloud Security","Azure","Conditional Access","Entra","CrowdStrike","Wiz","Zscaler","SIEM","Vulnerability Management","Incident Triage","EDR Platforms","Security Telemetry Analysis"],"x-skills-preferred":["Cloud Security Posture Management","Endpoint Detection and Response","Web Security","Security Operations","Threat Intelligence","Cloud Security","Azure","Conditional Access","Entra","CrowdStrike","Wiz","Zscaler","SIEM","Vulnerability Management","Incident Triage","EDR Platforms","Security Telemetry Analysis"],"datePosted":"2026-03-09T16:56:37.142Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Cloud Security Posture Management, Endpoint Detection and Response, Web Security, Security Operations, Threat Intelligence, Cloud Security, Azure, Conditional Access, Entra, CrowdStrike, Wiz, Zscaler, SIEM, Vulnerability Management, Incident Triage, EDR Platforms, Security Telemetry Analysis, Cloud Security Posture Management, Endpoint Detection and Response, Web Security, Security Operations, Threat Intelligence, Cloud Security, Azure, Conditional Access, Entra, CrowdStrike, Wiz, Zscaler, SIEM, Vulnerability Management, Incident Triage, EDR Platforms, Security Telemetry Analysis"}]}