Job Description
<div class="content-intro"><p>Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.</p></div><p><strong>ABOUT THE JOB:</strong></p>
<p>Anduril's Information Security team is looking for a Principal Detection and Response Engineer to focus on building world class defensive controls to protect the infrastructure around our advanced defense technology products. This is a role with wide berth that will have the latitude to design and implement cutting edge security architecture. As a Senior Staff engineer, you will act as a tech lead, providing technical leadership, vision, and guiding strategy within the Detection and Response team.</p>
<p><strong>WHAT YOU'LL DO:</strong></p>
<ul>
<li>Provide technical leadership, vision, and strategy for the advancement of the Detection and Response capability at Anduril</li>
<li>Collaborate with product security and engineering teams to architect and implement detection and response frameworks for Anduril’s products, assets, and other custom applications</li>
<li>Build and optimize tailored detection signatures, response playbooks, and response automation using detection-as-code principles</li>
<li>Lead threat modeling scenarios with cross-functional partners to understand weaknesses across OT, Cloud, Network, Endpoints, and other key worlds incorporating findings into security controls and/or detection signatures</li>
<li>Lead large-scale baselines of data with a heavy focus on manufacturing and IT/OT concepts, collaborating with Connected Factory, Security Engineering, and product teams to emit signals to incorporate into detections, new telemetry ingestion, and/or security controls</li>
<li>Contribute directly to the development and advancement of our detection-as-code, data engineering, automation, and infrastructure capabilities</li>
<li>Work cross-collaboratively with different teams to mature the detection and response of threat actors in key worlds, developing data baselines, automation, and engineering capabilities to scale this capability across the business</li>
<li>Mentor engineers and provide technical guidance to security team members, elevating detection engineering practices across the organization</li>
</ul>
<p><strong>REQUIRED QUALIFICATIONS:</strong></p>
<ul>
<li>Programming experience in one or more general purpose languages (Python, SQL, Go, Rust, etc)</li>
<li>Experience conducting data analysis in large-scale data lake environments</li>
<li>Experience deploying infrastructure as code (Terraform, CDK, CloudFormation, etc)</li>
<li>Experience working in a traditional software development lifecycle (i.e. Github, CI/CD, unit testing)</li>
<li>Extensive experience utilizing AWS / Azure security controls and services</li>
<li>Broad range of practical security knowledge across the spectrum of endpoint, network, identity, application, and cloud infrastructure</li>
<li>Strong knowledge of attacker tactics, techniques, and procedures (TTPs)</li>
<li>Strong communication skills and experience collaborating with internal and external stakeholders</li>
<li>Must be able to obtain and hold a U.S. Top Secret security clearance</li>
</ul>
<p><strong>PREFERRED QUALIFICATIONS:</strong></p>
<ul>
<li>Experience deploying infrastructure using Kubernetes (EKS) and/or Docker containers (ECS)</li>
<li>Experience conducting analysis / incid ... (truncated, view full listing at source)