Currently Empty: $0.00
Detection Engineering Specialist
$150K/Yr - $180K/Yr
hybrid, Remote
Posted 1 week ago
Job Summary
We are seeking a highly skilled Detection Engineering Specialist to design, develop, and optimize security detections that identify advanced cyber threats across enterprise environments. In this role, you will work closely with the Security Operations Center (SOC), Threat Hunting, Incident Response, and Threat Intelligence teams to build high-fidelity detection rules, automate security monitoring, and improve the organization’s ability to detect and respond to evolving threats.
The ideal candidate has experience with SIEM, EDR/XDR, detection engineering, scripting, and security analytics, along with a strong understanding of attacker techniques mapped to the MITRE ATT&CK framework.
Key Responsibilities
- Design, develop, and maintain high-quality detection rules for SIEM, EDR, cloud, and network security platforms.
- Create and optimize detection logic using Sigma, Kusto Query Language (KQL), Splunk SPL, or similar query languages.
- Develop use cases to detect ransomware, phishing, insider threats, credential theft, lateral movement, persistence, privilege escalation, and data exfiltration.
- Analyze attack techniques and map detections to the MITRE ATT&CK framework.
- Collaborate with Threat Intelligence teams to convert Indicators of Compromise (IOCs) and Threat Intelligence into actionable detection content.
- Improve detection coverage across endpoints, identities, cloud workloads, SaaS applications, and network infrastructure.
- Reduce false positives through tuning and continuous improvement of detection rules.
- Build automated detection workflows using SOAR platforms.
- Develop security dashboards, alerts, and analytics to improve SOC visibility.
- Support Incident Response teams by enhancing detection capabilities based on lessons learned from investigations.
- Conduct gap assessments to identify missing detection coverage.
- Create custom detections for emerging threats and zero-day vulnerabilities.
- Document detection logic, playbooks, and engineering standards.
- Stay current on cyber threats, malware trends, attacker tactics, and emerging detection techniques.
Required Qualifications
- Bachelor’s degree in Cyber Security, Computer Science, Information Technology, or a related field.
- 3–7+ years of experience in Detection Engineering, SOC, Threat Hunting, Incident Response, or Security Engineering.
- Strong knowledge of enterprise security monitoring and detection methodologies.
- Experience building and tuning SIEM detection rules.
- Hands-on experience with EDR/XDR platforms.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent communication and documentation abilities.
Required Technical Skills
Security Monitoring & SIEM
- Microsoft Sentinel
- Splunk Enterprise Security
- Google Security Operations (Chronicle)
- IBM QRadar
- Elastic Security
- Sumo Logic
Detection Engineering
- Sigma Rules
- Kusto Query Language (KQL)
- Splunk Search Processing Language (SPL)
- YARA
- Regular Expressions (Regex)
Endpoint Detection & Response (EDR/XDR)
- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne
- Cortex XDR
- VMware Carbon Black
Threat Intelligence
- MITRE ATT&CK
- STIX/TAXII
- MISP
- VirusTotal
- Recorded Future
- OpenCTI
Automation & SOAR
- Microsoft Sentinel Automation
- Cortex XSOAR
- Splunk SOAR
- Tines
Programming & Scripting
- Python
- PowerShell
- Bash
- SQL
Cloud Security
- Microsoft Azure
- Amazon Web Services (AWS)
- Google Cloud Platform (GCP)
Identity & Directory Services
- Microsoft Entra ID (Azure AD)
- Active Directory
- Okta
Networking
- TCP/IP
- DNS
- HTTP/HTTPS
- SMTP
- VPN
- Firewalls
- Proxy Logs
Operating Systems
- Windows
- Linux
- macOS
Preferred Qualifications
- Experience with threat hunting and malware analysis.
- Knowledge of detection-as-code methodologies.
- Experience securing hybrid and multi-cloud environments.
- Familiarity with Infrastructure as Code (Terraform or ARM/Bicep).
- Understanding of DevSecOps and CI/CD pipelines.
- Experience with purple team exercises and adversary emulation.
- Knowledge of Zero Trust architecture and identity security.
Preferred Certifications
- GIAC Certified Detection Analyst (GCDA)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Enterprise Defender (GCED)
- CompTIA CySA+
- CompTIA Security+
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Splunk Core Certified Power User
- CrowdStrike Certified Falcon Administrator
- Google Professional Cloud Security Engineer
Job Features
| Job Category | Cyber Security |



