Remote job
Senior Detection & Response Engineer
Job details
About this role
Role overview
This is a senior detection engineering role focused on Microsoft's security telemetry and tooling. The work centers on building detection coverage, mapping what Microsoft's signals actually contain in practice, and turning the gaps and changes into improvements that flow back into customer-facing security operations.
Responsibilities
- Own detection coverage across the Microsoft security stack - Build and maintain a working map of Microsoft security signal sources, including where documentation and reality disagree - Track changes in Microsoft telemetry and turn them into updates to detections, runbooks, and playbooks - Automate Microsoft-specific investigative workflows to speed up triage and response - Partner with engineering teams on Microsoft integrations and product feedback
Requirements
- Deep knowledge of the Microsoft security stack and how its telemetry behaves in practice - Fluency in KQL for querying, hunting, and authoring detections - Working knowledge of Graph and Graph Security APIs - Solid grasp of Windows internals and command line tooling - Experience writing, deploying, and tuning custom detections
Nice to have
- Comfort engaging directly with customers and explaining technical findings in plain language - Experience operating in a managed detection and response or security operations environment