Remote job
Senior Detection Engineer
Job details
About this role
Role overview A senior detection engineer is needed to lead the design, tuning, and continuous improvement of detection content within a globally distributed cyber defense organization. The position sits at the intersection of threat intelligence, incident response, and security automation, with responsibility for building detection coverage across cloud infrastructure, corporate endpoints, identity systems, and a multi-sided marketplace platform. The role requires participation in an on-call rotation and reports to a senior cyber defense manager.
Responsibilities - Design, implement, and maintain risk-based analytics and high-fidelity alerting tailored to specific use cases - Integrate external threat intelligence signals into detection pipelines - Develop agentic tooling and automation that measurably improves detection efficacy and efficiency - Engineer detections at scale using security telemetry, structured and unstructured logs, and custom data sources - Manage detection repositories, use case libraries, and ongoing content optimization - Coordinate with incident response, insider risk, threat hunting, and data pipeline teams on cross-functional detection projects - Mentor engineers and contribute to documentation, standards, and on-call operations
Requirements - 7+ years of experience in secure coding, alert development, and detection engineering - Direct experience building, maintaining, and operating a detection-as-code pipeline - Demonstrated success building automation that improved detection accuracy, velocity, or quality - Experience building agents or autonomous tooling to solve detection problems - Extensive knowledge of cloud-based and distributed systems - Mastery of SIEM query languages such as SQL, SPL, or KQL, plus programming proficiency in Python or Go - Experience mapping detections to frameworks like MITRE ATT&CK and D3FEND - Strong written and verbal communication, presentation, and stakeholder management skills
Nice to have - Hands-on experience with Snowflake, Cortex, or Google SecOps platforms