Sr. Signature Engineer

Total-TECH Co

Posted 30+ days ago

Experience

3 - 8 Years

Job Location

Cairo - Egypt

Education

Bachelor of Technology/Engineering

Nationality

Any Nationality

Gender

Not Mentioned

Vacancy

1 Vacancy

Job Description

Roles & Responsibilities

Responsibilities:

  • Design and develop signature rules to detect known and emerging threats using DPI technologies.
  • Analyze network traffic and protocols to extract identifying characteristics and behavioral patterns.
  • Reverse engineer malicious traffic or malware payloads to develop custom detection logic.
  • Test and validate signature accuracy, minimizing false positives and ensuring high performance.
  • Monitor signature effectiveness in live environments and iterate for improved detection and efficiency.
  • Collaborate with threat intelligence teams to stay ahead of evolving attack vectors.
  • Document and maintain a knowledge base of signature logic, rule sets, and configuration best practices.
  • Continuously research new protocols, applications, and evasion techniques to update detection logic.

Desired Candidate Profile

Requirements:

  • Proven expertise in Deep Packet Inspection (DPI) technologies and tools.
  • Strong understanding of network protocols (TCP/IP, HTTP/S, DNS, SMTP, etc.).
  • Experience in developing signature-based detection rules for IDS/IPS or DPI engines (e.g., Snort, Suricata, Bro/Zeek, YARA, etc.).
  • Ability to reverse engineer malware or obfuscated traffic to identify unique detection markers.
  • Strong experience in packet analysis tools like Wireshark, tcpdump, etc.
  • Proficient in regular expressions, scripting (Python, Shell), and pattern matching techniques.
  • Knowledge of cybersecurity threats, MITRE ATT&CK framework, and APT tactics and techniques.
  • Excellent analytical and problem-solving skills with strong attention to detail.
  • Strong documentation and communication abilities.

Company Industry

Department / Functional Area

Keywords

  • Sr. Signature Engineer

Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com