Remote job
Threat Detection Engineer
Job details
About this role
Role overview The role focuses on building the alerting layer for a privacy-first encrypted vault product used to store personal photos and videos. You will translate telemetry from cloud, application, and identity sources into high-fidelity detections that wake responders only when something meaningful is happening. The work is security engineering with a strong emphasis on reducing noise and supporting the SOC analysts who consume the rules.
Responsibilities - Author, tune, and maintain detection logic across cloud, application, and identity log pipelines - Track precision and recall over time and iterate on rules based on analyst feedback - Ingest and operationalize threat intelligence feeds covering credential abuse and cloud-targeted attack patterns - Build enrichment automations such as geolocation, ASN, and user context so triage is faster and more accurate - Maintain detection coverage maps tied to MITRE ATT&CK techniques or an internal threat model
Requirements - Hands-on experience in detection engineering or threat hunting with SIEM/SOAR platforms - Working knowledge of at least one query language such as KQL, SPL, or SQL, plus a scripting language - Familiarity with common SaaS attack paths including OAuth abuse, API key misuse, and storage misconfigurations - A collaborative approach to working with the analysts who consume your detections daily
Benefits and work setup - Remote-friendly hiring with global reach and async-first collaboration across time zones