ARCHIVED
This job listing has been archived and is no longer accepting applications.
MisuJob - AI Job Search Platform MisuJob

Security Research Engineer II – Threat Research & Detection Engineering

Elastic

Canada Remote permanent

Posted: January 16, 2026

Interested in this position?

Create a free account to apply with AI-powered matching

Quick Summary

Security Research Engineer II – Threat Research & Detection Engineering

Job Description

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.

What is the Role?

The Threat Research and Detection Engineering (TRaDE) team is responsible for developing and maintaining the prebuilt detection logic shipped with Elastic Security, researching emerging threats, validating detection efficacy, and engaging with the global community to democratize defensive capabilities.

We’re looking for a Security Research Engineer II with strong security fundamentals, hands-on detection engineering experience, and an interest in validating and improving defensive protections. This role focuses on driving threat research and real telemetry into high-quality, reliable, high efficacy, detection content.

What you’ll be doing:

This position centers on practical detection development and validation work across multiple data sources and attack surfaces. Responsibilities include writing and refining detection logic, validating rule behavior, and improving detection quality through telemetry analysis and testing.

Key focus areas include:

• Creating and refining detection logic across multiple domains (endpoint, cloud, identity, network, web, and email) domains using Elastic data sources.

• Validating rule behavior through functional testing, false-positive review, and iterative tuning.

• Evaluating attack paths across domains and contributing to coverage improvements throughout the kill chain.

• Analyzing multi-source telemetry to uncover detection opportunities and strengthen signal-to-noise ratios.

• Supporting cloud security validation efforts for AWS, Azure, or GCP detections.

• Collaborating with senior researchers to test new detection approaches and incorporate emerging attacker techniques.

• Using lightweight simulation tools or scripted tests to generate telemetry and validate detection behavior.

• Participating in Elastic Security Labs efforts, detection package updates, documentation, or community knowledge sharing when appropriate!

What you bring:

The ideal candidate brings solid security experience and a strong understanding of how attacker behaviors manifest in telemetry.

Beneficial strengths include:

• Experience in detection engineering, threat research, SOC operations, incident response, or related blue-team roles.

• Understanding of core concepts across multiple domains.

• Ability to write or validate detections using EQL, KQL, SQL, or similar query languages.

• Familiarity with MITRE ATT&CK, MITRE ATLAS, and its application to mapping detection coverage.

• Strong analytical and problem-solving skills, especially around false positives and weak-signal detection logic.

• Clear, collaborative communication and willingness to learn from and partner with senior researchers.

Bonus point desired experiences and interests:

• Understanding of the Elastic Security Solution, Elastic’s prebuilt rules, Elastic query languages, or the Elastic Common Schema.

• Experience with exposure validation, security control testing, or attack path validation platforms.

• Ability to generate or script test telemetry using Python, Bash, PowerShell, or simple simulation tools.

• Contributions to community detection content, blogs, OSINT research, or security rule repositories.

Additional Information - We Take Care of Our People

As a distributed company, diversity drives our identity. Whether you’re looking to launch a new career or grow an existing one, Elastic is the type of company where you can balance great work with great life. Your age is only a number. It doesn’t matter if you’re just out of college or your children are; we need you for what you can do.

We strive to have parity of benefits across regions and while regulations differ from place to place, we believe taking care of our people is the right thing to do.

• Competitive pay based on the work you do here and not your previous salary

• Health coverage for you and your family in many locations

• Ability to craft your calendar with flexible locations and schedules for many roles

• Generous number of vacation days each year

• Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service

• Up to 40 hours each year to use toward volunteer projects you love

• Embracing parenthood with minimum of 16 weeks of parental leave

Different people approach problems differently. We need that. Elastic is an equal opportunity employer and is committed to creating an inclusive culture that celebrates different perspectives, experiences, and backgrounds. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, pregnancy, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, disability status, or any other basis protected by federal, state or local law, ordinance or regulation.

We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email [email protected]. We will reply to your request within 24 business hours of submission.

Applicants have rights under Federal Employment Laws, view posters linked below: Family and Medical Leave Act (FMLA) Poster; Pay Transparency Nondiscrimination Provision Poster; Employee Polygraph Protection Act (EPPA) Poster and Know Your Rights (Poster)

Elasticsearch develops and distributes technology and information that is subject to U.S. and other countries’ export controls and licensing requirements for individuals who are located in or are nationals of the following sanctioned countries and regions: Belarus, Cuba, Iran, North Korea, Syria, or Russia, including the Ukrainian territories annexed by Russia (The Crimea region of Ukraine, The Donetsk People's Republic (DNR), The Luhansk People's Republic (LNR), Kherson or Zaporizhzhia). If you are located in or are a national of one of the listed countries or regions, an export license may be required as a condition of your employment in this role. Please note that national origin and/or nationality do not affect eligibility for employment with Elastic.

Please see here for our Privacy Statement.

Why Apply Through MisuJob?

AI-Powered Job Matching: MisuJob uses advanced artificial intelligence to analyze your skills, experience, and career goals. Our matching algorithm compares your profile against thousands of job requirements to find positions where you have the highest chance of success. This saves you hours of manual job searching and ensures you only see relevant opportunities.

One-Click Applications: Once you create your profile, applying to jobs is effortless. Your resume and cover letter are automatically tailored to highlight the most relevant experience for each position. You can apply to multiple jobs in minutes, not hours.

Career Intelligence: Beyond job matching, MisuJob provides valuable career insights. See how your skills compare to market demands, identify skill gaps to address, and understand salary benchmarks for your experience level. Make data-driven decisions about your career path.

Frequently Asked Questions

How do I apply for this position?

Click the "Register to Apply" button above to create a free MisuJob account. Once registered, you can apply with one click and track your application status in your dashboard.

Is MisuJob free for job seekers?

Yes, MisuJob is completely free for job seekers. Create your profile, get matched with jobs, and apply without any cost. We help you find your dream job without any hidden fees.

How does AI matching work?

Our AI analyzes your resume, skills, and experience to understand your professional profile. It then compares this against job requirements using natural language processing to calculate a match percentage. Higher matches mean better fit for the role.

Can I apply to jobs in other countries?

Absolutely. MisuJob features jobs from companies worldwide, including remote positions. Filter by location or look for remote opportunities to find jobs that match your preferences.

Ready to Apply?

Join thousands of job seekers using MisuJob's AI to find and apply to their dream jobs automatically.

Register to Apply