Staff Analytics Engineer at Dragos

United States

Dragos Logo
Not SpecifiedCompensation
Senior (5 to 8 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, Operational Technology, Industrial Control SystemsIndustries

Requirements

  • 4 years in a production software development environment, with 2 years of experience with Python development
  • 6+ years in cyber security related field; operations, threat hunting, detection development, offensive operations, threat emulation, security research, or security tool development
  • Experience with analysis of network packet captures (PCAPs) and traffic using tools such as Wireshark and Network Miner
  • High level of experience using Suricata, Wireshark/tshark for network packet capture (PCAPs) analysis, and SIEM tools
  • Familiarity with containerized solutions for debugging
  • A solid understanding of both Linux and Windows command line tools for debugging
  • A strong ability to conduct open-source research
  • Experienced with git (or other software version control solutions)
  • ICS/OT knowledge and experience
  • Experience developing in Rust or applying AI/ML techniques in production environments is a plus
  • Familiarity with building data pipelines using Python and cloud platforms (AWS, GCP, or Azure), along with SQL, data normalization, and data warehousing experience is beneficial
  • Exposure to OT technologies, such as PLC programming or HMI configuration, is nice to have
  • Knowledge of tools like Zeek or Yara for threat detection or network analysis is helpful
  • Experience with the ELK stack (Elasticsearch, Logstash, Kibana) for log and event analysis is a plus

Responsibilities

  • Participate in efforts for discovering and cataloging OT assets using advanced detection methodologies
  • Work in tandem with reverse engineers to decipher proprietary protocols and uncover asset attributes using vendor documentation and protocol specifications
  • Partner with developers to integrate findings into Dragos’s threat detection and response platform
  • Contribute to the creation of detection logic and rules for real-time threat monitoring of atomic operations
  • Troubleshoot and fix both internal engine configurations and Python analytics used for asset identification and atomic operations
  • Develop and document team CI/CD and testing standards, authoring unit, integration, and end-to-end tests to verify characterizations and detections are working as expected
  • Collect PCAPs using OSINT, generate PCAPs utilizing test range, or craft PCAPs utilizing software to use in both detection development and regression testing

Skills

Python
CI/CD
OT asset discovery
protocol analysis
reverse engineering
threat detection
detection logic
unit testing
integration testing
ICS cybersecurity

Dragos

Cybersecurity for industrial control systems

About Dragos

Dragos specializes in cybersecurity for industrial control systems (ICS) and operational technology (OT) environments, which are essential for industries like manufacturing, energy, and transportation. Their main product, the Dragos Platform, allows organizations to visualize their network, detect threats, and respond effectively to cyberattacks. This platform is particularly important because many ICS and OT systems are outdated and vulnerable to attacks that could impact public safety and economic stability. Dragos differentiates itself by focusing specifically on the unique needs of these industrial sectors, providing both a comprehensive platform and consulting services to help clients enhance their cybersecurity strategies. The company's goal is to protect critical industrial assets from cyber threats, ensuring the safety and reliability of essential services across various industries.

Glen Burnie, MarylandHeadquarters
2016Year Founded
$420.4MTotal Funding
SERIES_DCompany Stage
Consulting, Industrial & Manufacturing, CybersecurityIndustries
501-1,000Employees

Benefits

Medical, dental, vision, disability, & life insurance
401k with match
Equity
Competitive compensation
Remote working options
Pet-friendly options
In-house brewery

Risks

Emerging OT cybersecurity firms may erode Dragos' market share.
Rapid evolution of ransomware tactics may outpace Dragos' detection capabilities.
Integration of new acquisitions may face operational challenges.

Differentiation

Dragos specializes in cybersecurity for industrial control systems and operational technology environments.
The Dragos Platform offers comprehensive visibility, threat detection, and rapid response tools.
Dragos provides consulting services to enhance strategic cybersecurity roadmaps for organizations.

Upsides

Rising ransomware attacks increase demand for Dragos' OT cybersecurity solutions.
Strategic partnerships enhance Dragos' service offerings and customer trust.
Acquisition of Network Perception strengthens Dragos' platform capabilities.

Land your dream remote job 3x faster with AI