
Detection Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Design, develop, and take ownership of high-fidelity detections across AWS, Azure, GCP, Okta, Entra ID, EDR, and various SaaS log sources from hypothesis through to production.
• Manage detection content as software, utilizing version control, peer review, automated validation and testing, and CI/CD deployment within customer environments.
• Evaluate detection coverage against MITRE ATT&CK, identify gaps, and address them based on actual threat activities.
• Create and execute attack simulations and test harnesses to verify true positives and benign activities.
• Assess detection performance, refine false positives and negatives, and phase out ineffective detections.
• Leverage AI-assisted workflows to craft, convert, test, and document detection rules, while developing reliable AI-generated detection tools.
• Establish behavioral baselines and design anomaly detections for identity, cloud, and SaaS activities.
• Develop detections that provide comprehensive, structured context for AI-driven investigations.
• Convert threat intelligence, incident findings, and threat hunt outcomes into sustainable behavioral detection logic.
• Collaborate with Apollo analysts and security researchers to enhance detections and document alerts.
• Adapt and fine-tune detection content to fit customer environments and business contexts.
• Over 5 years of practical experience in cybersecurity, with a significant focus on detection engineering.
• Demonstrated expertise in designing, building, and tuning detections at scale across SIEM, EDR, or custom detection platforms.
• Strong command of Sigma, KQL, SPL, or YARA-L.
• Proficiency in coding, ideally in Python, for automation and testing purposes.
• In-depth understanding of MITRE ATT&CK and attacker tactics, techniques, and procedures pertaining to cloud, identity, endpoint, and SaaS telemetry.
• Experience with Git, peer review, automated testing, and CI/CD for detection content development.
• Familiarity with AI tools for detection authoring, tuning, or validation.
• Proven experience in developing behavioral or anomaly-based detections and setting activity baselines.
• Strong skills in log analysis with the capability to differentiate between malicious activities and benign noise.
• Excellent written and verbal communication skills for documenting detection logic and articulating coverage and trade-offs.
• Bonus: experience in Managed Detection and Response (MDR), Managed Security Service Provider (MSSP), or high-volume Security Operations Center (SOC) environments.
• Bonus: familiarity with Atomic Red Team or purple teaming methodologies.
• Bonus: background in threat hunting or cloud incident response.
• Bonus: experience with UEBA or statistical/machine learning-based detection methods.
• Bonus: involvement in building AI-assisted detection or investigation tools.
• Bonus: contributions to open-source detection content or the detection engineering community.
• Top-of-market equity component.
• Competitive compensation.
• Autonomy to influence the direction of operations and take ownership of outcomes.
• Opportunities for mentorship and learning.
• An inclusive work environment.
Highland Electric Fleets
Falconwood, Incorporated
Aira
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.