Senior Detection Engineer
ZScaler
About the role
About Zscaler
Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.
We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.
Role
We’re looking for a Senior Detection Engineer to join our team. The role will be located in Costa Rica reporting to the Senior Manager of Threat Hunting as part of the Zscaler Threat Hunting team.
Detection Engineers are responsible for advancing threat detection and hunting capabilities of our managed threat hunting service: Zscaler Threat Hunting. This role involves combining Threat Researcher and Detection Engineering skills to develop next-generation detection logic for our threat hunters, utilizing tools like Python, SQL AWS services, YAML-based detection logic, and SIGMA-like rules. The role also contributes to the scalability and maintenance of engineering projects, leveraging data platforms such as Hadoop and Athena. Finally, this position requires independently writing and updating detections and playbooks, which includes working flexible hours, such as weekend night shifts and providing on-call support.
What We're Looking for (Minimum Qualifications)
Hands-on experience developing and implementing detection rules in a Security Information and Event Management (SIEM) tool, such as Splunk, Microsoft Sentinel, or ElasticSearch
Familiarity with MITRE ATT&CK framework and experience translating TTPs into actionable detection logic
Scripting and automation skills using Python for developing and managing detection infrastructure
Must have excellent reporting and analytical skills and experience writing and optimizing IDS/IPS and YARA signatures
Must be able to validate detection logic, perform root cause analysis of detection