
Senior Security Engineer, Detection Engineering
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in California, +2 more states.
• Develop and refine high-confidence detections utilizing Splunk, Microsoft Sentinel / Defender, CrowdStrike, cloud-native logs, identity telemetry, endpoint data, SaaS platforms, and developer systems.
• Convert incidents, hunts, threat intelligence, red-team discoveries, and vulnerability context into actionable detection logic.
• Analyze real telemetry, focusing on field behavior, timing, joins, baselines, and false positives prior to generating alerts.
• Oversee the entire detection lifecycle, including design, query development, validation, peer review, documentation, deployment, tuning, monitoring, and eventual retirement.
• Enhance detection-as-code workflows by implementing test data, quality assurance, metadata, rollout safety, coverage tracking, and detection health reporting.
• Collaborate with responders to minimize noise, provide context, enhance severity evaluations, and create follow-up detections.
• Define logging, normalization, enrichment, and retention requirements whenever crucial telemetry is absent or challenging to utilize.
• Mentor analysts and engineers during design reviews, query assessments, and provide guidance on credible detections.
• Over 8 years of experience in detection engineering, security engineering, threat hunting, incident response, SOC engineering, or information security monitoring.
• A degree in Computer Science, Cybersecurity, Engineering, or equivalent professional experience.
• Practical experience in developing and fine-tuning detections within a major SIEM or security analytics platform.
• Proficient in query and scripting languages, particularly SPL, KQL, SQL, Python, or similar.
• Solid understanding of attacker behavior across identity, endpoint, cloud, network, email, collaboration tools, developer infrastructure, secrets, and data exfiltration.
• Capability to transform raw logs into production-ready detection content, considering field semantics, thresholds, joins, baselines, false positives, missing data, and triage context.
• Familiarity with Git, code reviews, automated checks, CI/CD processes, documentation, and operational ownership.
• Ability to articulate the value of detections, their limitations, subsequent steps, and circumstances under which alerts should not be issued.
• Experience or knowledge in detection-as-code initiatives, cloud technologies, identity management, Kubernetes, CI/CD, supply chain security, AI tools, developer systems, incident response, threat hunting, red teaming, purple teaming, malware analysis, forensics, replay testing, synthetic telemetry, attack emulation, detection unit testing, or coverage reporting is a plus.
• Equity
• Benefits
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.