Remotery

Detection Engineer

Posted Jul 31

This is a fully remote position, open to applicants in Texas.

📋 Description

• Design and execute detection strategies utilizing a detection-as-code methodology across SIEM platforms (e.g., Splunk, Sentinel, Chronicle) and EDR solutions (e.g., CrowdStrike, Cortex XDR, SentinelOne).

• Create and operationalize detection logic in formats such as YAML/Sigma/YARA-L, while also handling documentation, tuning, testing, and version management.

• Utilize APIs to streamline rule deployment, validation, and telemetry analysis—minimizing dependence on graphical user interfaces.

• Collaborate with Threat Intel, Incident Response, and Cloud Security teams to develop threat-informed detection mechanisms based on actual attack patterns.

• Engage in threat modeling initiatives to pinpoint high-value detection prospects and identify coverage deficiencies.

• Examine telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to discover detection use cases and ensure readiness of telemetry.

• Take part in adversary simulation and detection validation activities employing tools such as Atomic Red Team, Caldera, or custom scripts.

• Assist in documenting detection logic, the rationale behind coverage, and guidance for responses.

• Proactively contribute to the ongoing enhancement of detection engineering processes, tools, and standards.


⛳️ Requirements

• 2–5+ years of practical experience in detection engineering, threat hunting, or incident response.

• Strong expertise in Python and REST APIs for engaging with EDR/SIEM platforms and automating detection processes.

• Proven experience in writing, fine-tuning, and validating detection logic in at least one of the following: Sigma, YARA-L, Splunk SPL, KQL, XQL.

• Familiarity with telemetry sources, including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.

• Understanding of MITRE ATT&CK and the capability to align detections with adversary tactics and potential detection failures.

• Ability to rapidly learn new security technologies and adjust detection strategies as needed.

• Comfortable in a dynamic environment where threat-driven detection and swift iteration are commonplace.


🏝️ Benefits

• Competitive medical, dental, and vision benefits for employees and their dependents.

• 401k matching program that vests with every payroll.

• A flexible and remote-friendly workplace.

• Opportunities for training to enhance your skill set.

People also viewed

LiteLLM AI Gateway14 hours ago

Forward Deployed Engineer

IN flagIndia OnlyFull-timeEngineer$50k – $90k/year
ApplyView job
Snowflake20 hours ago

Principal Threat Intelligence Engineer

US flagCalifornia OnlyFull-timeEngineer$249k – $357.6k/year
ApplyView job
RTX20 hours ago

Flammability Certification Engineer II

US flagNorth Carolina OnlyFull-timeEngineer$68.9k – $131.1k/year
ApplyView job
C-MORE23 hours ago

Product Strategist – Environmental Engineer

Anywhere in the WorldFull-timeEngineer
ApplyView job
SGS23 hours ago

Part-time Field Evaluation Engineer

GA flagGabon OnlyFull-timeEngineer$40 – $50/hour
ApplyView job
TRC Worldwide Engineering, Inc.1 day ago

Structural Forensic Engineer

US flagTennessee OnlyFull-timeEngineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers