Remote job
Detection Engineering Lead
Job details
About this role
Role overview A senior detection engineering lead is needed to own the detection program for a large U.S. consumer lender whose 24/7 security operations are delivered by a distributed nearshore team. The role combines hands-on rule authoring with people leadership, sitting at the intersection of identity, endpoint, and cloud telemetry and the analysts who act on it. The lead will set priorities, validate the work of two senior detection engineers, and report detection coverage directly to client security leadership.
Responsibilities - Manage the full detection inventory, including new use cases, tuning, health monitoring, and retirement, with clear ownership for each item. - Prioritize detection work using threat intelligence, hunt findings, incident lessons, and Tier 2 analyst feedback, focusing on techniques most relevant to consumer lending. - Build identity-centric detections on Okta, custom IOAs in CrowdStrike and Microsoft Defender, and AWS control-plane coverage using CloudTrail and GuardDuty. - Diagnose issues across the telemetry chain, including data that reaches a pipeline layer but never makes it to the SIEM, and alerts that fire but do not open cases. - Operate detections as code with version control, peer review, simulated-attack testing, and documented change records that the client approves before behavior shifts. - Produce MITRE ATT&CK coverage reporting for client security leaders, including known gaps, and mentor the two senior detection engineers on the team.
Requirements - Several years of hands-on experience writing and tuning production detections on a SIEM or analytics platform, with the ability to explain the reasoning behind a shipped rule. - Solid grasp of log pipelines, including how data can be lost, mis-parsed, or mis-enriched between source and alert. - Engineering discipline: detections treated as code with versioning, peer review, and pre-release testing, plus the ability to articulate coverage limits to stakeholders. - Demonstrated experience mentoring or leading engineers remotely and giving candid, constructive reviews of their work. - Comfortable presenting detection coverage, including gaps, to client security leadership. - Based in the United States on Eastern Time business hours, with periodic travel to the client and to Bogotá and Buenos Aires; must be permanently authorized to work in the U.S. and able to pass background checks.
Nice to have - Hands-on Elastic Security (EQL, ES|QL, KQL); experience with Splunk, Sentinel, or Chronicle is also relevant. - Familiarity with Abstract Security or Cribl-style data pipeline tooling. - Custom IOAs in CrowdStrike Falcon and advanced hunting in Microsoft Defender. - Financial services exposure under NYDFS Part 500, SOX, or PCI DSS. - Experience applying GenAI to detection work with proper evaluation behind it. - Testing and automation skills with Sigma, YARA, Atomic Red Team, Caldera, Python, and SOAR playbooks. - Certifications such as GCDA, GCIA, GCED, SC-200, or Elastic.
Benefits and work setup - Remote work from the United States with business hours anchored to Eastern Time. - Periodic travel to the client and to nearshore team locations in Bogotá and Buenos Aires. - Visa sponsorship is not offered for this role.