
Senior Cybersecurity Detection & Threat Intelligence Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Design, implement, and continuously optimize threat detection mechanisms across SIEM, EDR/XDR, OT security platforms, and cloud-native security tools.
• Take ownership of the complete detection engineering lifecycle, which includes hypothesis formulation, rule creation, validation, deployment, tuning, and retirement, in alignment with MITRE ATT&CK across IT, OT, cloud, and identity environments.
• Operationalize threat intelligence by converting finished intelligence, IOCs, and adversary TTPs into actionable detection rules, hunting hypotheses, and automated enrichment workflows.
• Oversee and maintain threat intelligence feeds and platforms, encompassing ingestion, validation, confidence scoring, and the management of IOC libraries.
• Develop, sustain, and enhance SOAR automation playbooks, enrichment pipelines, and detection workflows to improve alert accuracy and minimize analyst workload.
• Create and maintain detection content for OT/ICS environments, focusing on industrial protocol anomaly detection, Purdue model segmentation visibility, and OT-specific threat actor TTPs.
• Enhance the quality and coverage of security telemetry by collaborating with infrastructure, network, cloud, OT, and platform engineering teams to incorporate new log sources and validate data integrity.
• Candidates must reside in India; this role is approved for India-based applicants only.
• 7–10+ years of experience in cybersecurity with a focus on detection engineering, security operations, or threat intelligence.
• Practical experience with SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or QRadar, including rule creation, query development, and data onboarding.
• In-depth understanding of adversary tactics, techniques, and procedures, along with experience in mapping detections to MITRE ATT&CK.
• Practical experience in developing detection rules, correlation logic, behavioral analytics, and threshold-based alerting across various telemetry sources.
• Experience using SOAR platforms for automated enrichment pipelines, detection workflows, and operationalizing threat intelligence.
• Strong scripting and automation capabilities in Python, PowerShell, or KQL for detection development, data parsing, and workflow automation.
• Experience with threat intelligence platforms for IOC lifecycle management, feed integration, and operationalizing intelligence-to-detection.
• Preferred: experience in building or enhancing detection engineering programs, including backlog management, coverage gap analysis, and maintaining ATT&CK heatmaps.
• Preferred: familiarity with OT/ICS security monitoring.
• Preferred: knowledge of threat intelligence integration and threat hunting methodologies.
• Preferred: understanding of detection-as-code, version control for detection content, and automated rule testing pipelines.
• Preferred: knowledge of cloud-native security monitoring and identity telemetry.
• Preferred: relevant certifications such as GDAT, GCDE, GCIA, GCED, or equivalent credentials.
• Comprehensive benefits package including health, dental, and vision insurance.
• Opportunities for professional development and continued education.
• Flexible work arrangements and a supportive work environment.
• Competitive salary and performance-based bonuses.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.