Remotery

Senior Security Engineer, Detection Engineering

Posted 6 days ago

This is a fully remote position, open to applicants in California, +2 more states.

📋 Description

• Develop and refine high-confidence detections utilizing Splunk, Microsoft Sentinel / Defender, CrowdStrike, cloud-native logs, identity telemetry, endpoint data, SaaS platforms, and developer systems.

• Convert incidents, hunts, threat intelligence, red-team discoveries, and vulnerability context into actionable detection logic.

• Analyze real telemetry, focusing on field behavior, timing, joins, baselines, and false positives prior to generating alerts.

• Oversee the entire detection lifecycle, including design, query development, validation, peer review, documentation, deployment, tuning, monitoring, and eventual retirement.

• Enhance detection-as-code workflows by implementing test data, quality assurance, metadata, rollout safety, coverage tracking, and detection health reporting.

• Collaborate with responders to minimize noise, provide context, enhance severity evaluations, and create follow-up detections.

• Define logging, normalization, enrichment, and retention requirements whenever crucial telemetry is absent or challenging to utilize.

• Mentor analysts and engineers during design reviews, query assessments, and provide guidance on credible detections.


⛳️ Requirements

• Over 8 years of experience in detection engineering, security engineering, threat hunting, incident response, SOC engineering, or information security monitoring.

• A degree in Computer Science, Cybersecurity, Engineering, or equivalent professional experience.

• Practical experience in developing and fine-tuning detections within a major SIEM or security analytics platform.

• Proficient in query and scripting languages, particularly SPL, KQL, SQL, Python, or similar.

• Solid understanding of attacker behavior across identity, endpoint, cloud, network, email, collaboration tools, developer infrastructure, secrets, and data exfiltration.

• Capability to transform raw logs into production-ready detection content, considering field semantics, thresholds, joins, baselines, false positives, missing data, and triage context.

• Familiarity with Git, code reviews, automated checks, CI/CD processes, documentation, and operational ownership.

• Ability to articulate the value of detections, their limitations, subsequent steps, and circumstances under which alerts should not be issued.

• Experience or knowledge in detection-as-code initiatives, cloud technologies, identity management, Kubernetes, CI/CD, supply chain security, AI tools, developer systems, incident response, threat hunting, red teaming, purple teaming, malware analysis, forensics, replay testing, synthetic telemetry, attack emulation, detection unit testing, or coverage reporting is a plus.


🏝️ Benefits

• Equity

• Benefits

People also viewed

ASG Technologies6 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike6 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International7 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape7 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity8 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist10 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers