HalcyonHA

Security Alert System Developer

Threats like ransomware are designed to evade modern security tools, and just one miss can have a catastrophic impact on your organization.

Halcyon

Employee count: 51-200

What we do:
Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware.

Who we are:
Halcyon was formed in 2021 by a team of cyber industry veterans after battling the scourge of ransomware (and advanced threats) for years at some of the largest global security vendors. Comprised of leaders from Cylance (now Blackberry), Accuvant (now Optiv), Fireye and ISS X-Force (now IBM), Halcyon is focused on building products and solutions for mid-market and enterprise customers.

As a remote-native, completely distributed global team, we recognize great talent can exist anywhere. We invite you to apply to a job you’re interested in and we'll work a plan to meet your needs.

About the Project

We're developing a sophisticated security alert management system for enterprise environments. The system integrates with the Halcyon security platform to process, analyze, and facilitate the triage of security alerts. Our solution helps security teams efficiently categorize threats, distinguish between true and false positives, and maintain appropriate response protocols.

Role Overview

We're seeking an experienced Python developer with a strong background in security operations to join our team. This role involves enhancing and maintaining a critical security alert processing and triage system that security analysts rely on daily to identify and respond to potential threats.

Key Responsibilities

  • Develop, maintain, and enhance Python-based security alert processing systems

  • Implement integrations with security APIs including VirusTotal and Halcyon's security platform

  • Design and improve user interfaces for security alert triage via Slack interfaces

  • Create and maintain secure database operations for alert storage and tracking

  • Implement automated threat classification and scoring mechanisms

  • Optimize alert processing workflows to reduce analyst fatigue and improve response times

  • Collaborate with security operations teams to ensure system effectiveness

Required Skills & Experience

  • 7+ years of Python development experience, particularly with API integrations

  • Experience with security platforms and security alert management

  • Familiarity with threat intelligence concepts and security operations workflows

  • Knowledge of database systems (particularly SQLite) and SQL query optimization

  • Understanding of RESTful API design and consumption

  • Experience with asynchronous programming and multi-threading in Python

  • Ability to work with JSON data structures and API responses

Preferred Qualifications

  • Experience with Slack API integrations and interactive message components

  • Knowledge of security tooling (VirusTotal, YARA rules, etc.)

  • Understanding of malware analysis and classifications

  • Familiarity with container technologies (Docker, Kubernetes)

  • Experience with cloud security concepts and platforms

  • Security certifications (CISSP, OSCP, Security+, etc.)

  • Experience with Flask or other lightweight web frameworks

Technical Environment

You'll be working with:

  • Python 3.x

  • SQLite for database operations

  • RESTful APIs (Halcyon, VirusTotal, etc.)

  • Slack API for interactive alerts

  • JSON data processing

  • GitHub for version control

  • YARA rules for threat detection

  • Flask for web service components

Project Specifics

This system handles the following key functions:

  • Processing incoming security alerts from various sources

  • Enriching alerts with threat intelligence data

  • Presenting critical alert information to security analysts

  • Facilitating informed decision-making on alert triage (true positive/false positive)

  • Maintaining records of alert dispositions and analyst notes

  • Automating routine alert handling based on established patterns

  • Generating reports on alert trends and analyst activities

Collaboration EnvironmentYou'll work closely with security operations teams to understand their workflows and challenges. The ideal candidate should have strong communication skills and the ability to translate security analyst needs into effective technical solutions.

In accordance with applicable state and federal laws, the range provided is Halcyon’s reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. Base pay is one part of the total package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and equity in the Company.

We understand it takes a diverse team of highly intelligent, passionate, curious, and creative people to develop the exceptional product we are building. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity employer.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Location requirements

Open to candidates from all countries.

Hiring timezones

Worldwide

About Halcyon

Learn more about Halcyon and their company culture.

View company profile

Threats like ransomware are designed to evade modern security tools, and just one miss can have a catastrophic impact on your organization. Halcyon is the first Anti-Ransomware and Cyber Resilience Platform with automated encryption key capture and autonomous decryption capabilities to keep your operations running 24/7/365.

Most security vendors are quick to update their solutions once a threat is seen in the real world. But what if you are one of the first victims? Without a dedicated anti-ransomware engine, the protection gap can range from 24 hours to several days or even weeks. Traditional rules-based EDR and other endpoint protection products rely on convolutional neural network AI models for detection that are generally too complex to quickly train on emerging threats. In contrast, Halcyon leverages Capsule Networks (CapsNets) AI micro-models that allow us to rapidly train, test and deploy new protection mechanisms to address novel and emerging threats exponentially faster than traditional endpoint tools.

After gaining initial access to a system, attackers will routinely target security tools active on an endpoint. Bypassing and unhooking these products has a lower resource cost than attempting to sneak malicious binaries or scripts past automated detection tools. With countless real-world bypasses published, it is clear that security products also need to be hardened against attacks. The Halcyon agent specifically prevents leading endpoint tools from being disabled, bypassed or unhooked.

Ransomware events can seriously disrupt business operations, that is why our resilience engine was designed to recover infected systems as quickly as possible. Once a ransomware incident occurs, the remediation clock starts ticking. While Halcyon delivers the most advanced detection and prevention capabilities in the market, we also provide the only automated resilience layer to assure a ransomware attack never slips by your defenses. Halcyon is enabled with automated encryption key capture and autonomous decryption capabilities that immediately decrypt any infected devices.

Employee benefits

Learn about the employee benefits and perks provided at Halcyon.

View benefits

Equity benefits

We offer competitive compensation packages with equity.

Life insurance

Halcyon offers life insurance as part of its benefits package.

Paid parental leave

Halcyon offers paid time off to care for and bond with a new child.

Short & long term disability insurance

Halcyon provides short and long-term disability insurance for its employees.

View Halcyon's employee benefits
Claim this profileHalcyon logoHA

Halcyon

Company size

51-200 employees

Founded in

2021

Chief executive officer

Jon Miller

Employees live in

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

33 remote jobs at Halcyon

Explore the variety of open remote roles at Halcyon, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Halcyon

Remote companies like Halcyon

Find your next opportunity by exploring profiles of companies that are similar to Halcyon. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 85,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Halcyon hiring Security Alert System Developer • Remote (Work from Home) | Himalayas