
Detection Engineer
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Texas.
• Design and execute detection strategies utilizing a detection-as-code methodology across SIEM platforms (e.g., Splunk, Sentinel, Chronicle) and EDR solutions (e.g., CrowdStrike, Cortex XDR, SentinelOne).
• Create and operationalize detection logic in formats such as YAML/Sigma/YARA-L, while also handling documentation, tuning, testing, and version management.
• Utilize APIs to streamline rule deployment, validation, and telemetry analysis—minimizing dependence on graphical user interfaces.
• Collaborate with Threat Intel, Incident Response, and Cloud Security teams to develop threat-informed detection mechanisms based on actual attack patterns.
• Engage in threat modeling initiatives to pinpoint high-value detection prospects and identify coverage deficiencies.
• Examine telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to discover detection use cases and ensure readiness of telemetry.
• Take part in adversary simulation and detection validation activities employing tools such as Atomic Red Team, Caldera, or custom scripts.
• Assist in documenting detection logic, the rationale behind coverage, and guidance for responses.
• Proactively contribute to the ongoing enhancement of detection engineering processes, tools, and standards.
• 2–5+ years of practical experience in detection engineering, threat hunting, or incident response.
• Strong expertise in Python and REST APIs for engaging with EDR/SIEM platforms and automating detection processes.
• Proven experience in writing, fine-tuning, and validating detection logic in at least one of the following: Sigma, YARA-L, Splunk SPL, KQL, XQL.
• Familiarity with telemetry sources, including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
• Understanding of MITRE ATT&CK and the capability to align detections with adversary tactics and potential detection failures.
• Ability to rapidly learn new security technologies and adjust detection strategies as needed.
• Comfortable in a dynamic environment where threat-driven detection and swift iteration are commonplace.
• Competitive medical, dental, and vision benefits for employees and their dependents.
• 401k matching program that vests with every payroll.
• A flexible and remote-friendly workplace.
• Opportunities for training to enhance your skill set.
LiteLLM AI Gateway
Snowflake
RTX
C-MORE
Get handpicked remote jobs straight to your inbox weekly.