
Cybersecurity Engineer
Barracuda Networks, Inc.2 months ago
Chelmsford, MA, USASenior
Base Salary
$114k - $152k/yr
Responsibilities
- Research emerging cyber threats, vulnerabilities, exploits, malware, adversary campaigns, and attacker tradecraft.
- Analyze adversary tactics, techniques, and procedures and translate findings into detection requirements, analytics, and defensive improvements.
- Identify detection gaps and blind spots across telemetry, security controls, and product capabilities.
- Develop, improve, and validate detection strategies for known and emerging adversary behaviors.
- Conduct controlled adversary simulations, purple team exercises, Attack & Defend exercises, and other attack validation activities.
- Develop and maintain repeatable attack simulations, offensive security tooling, automation, and cloud-based security research laboratories.
- Collaborate with Threat Intelligence, Security Operations, Incident Response, Product, and Engineering teams to improve detection and response capabilities.
- Communicate technical findings, attack paths, detection gaps, and recommended mitigations to technical and non-technical audiences.
- Mentor security professionals and contribute to security research, threat reports, technical assessments, and internal briefings.
Requirements
- 5+ years of hands-on experience in offensive security, threat research, detection engineering, threat intelligence, incident response, or a closely related discipline.
- Strong understanding of modern attacker tradecraft and experience researching vulnerabilities, exploits, malware, or emerging attack techniques.
- Experience translating adversary behaviors and TTPs into detection opportunities or defensive requirements.
- Hands-on experience with adversary emulation, red teaming, penetration testing, or attack simulation.
- Experience developing or validating detections using SIEM, EDR, XDR, network, cloud, identity, or other security telemetry.
- Strong understanding of the MITRE ATT&CK framework and complex attack chains.
- Strong scripting or programming skills in Python, PowerShell, Bash, or similar languages.
- Hands-on experience with Windows, Unix, and Linux operating systems, network protocols, enterprise security architecture, and cloud environments such as AWS or Azure.
- Preferred experience includes adversary emulation tooling, automated attack simulations, detection analytics, detection-as-code, threat hunting, vulnerability research, purple team exercises, and open-source security research.
- Relevant certifications such as OSCP, OSEP, OSCE, GXPN, GCIA, GCIH, or CEH are highly valued.
Benefits
- High-quality health benefits.
- Retirement plan with employer match.
- Career-growth opportunities, internal mobility, and cross-training.
- Flexible Time Off and Paid Time Off benefits.
- Volunteer opportunities.
- Remote work is indicated by the #LI-remote designation.