
Senior Threat Detection Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Design, construct, test, and optimize detections as code (KQL) utilizing a GitOps workflow.
• Align detections with the MITRE ATT&CK framework, identify coverage gaps, and prioritize resource allocation based on the threat landscape.
• Evaluate community and vendor rule releases, such as Sigma, to determine what to implement, modify, or ignore.
• Decrease alert noise by fine-tuning and phasing out ineffective rules while monitoring detection quality metrics.
• Strategize and execute hypothesis-driven threat hunts across cloud environments, SaaS platforms, identity systems, endpoint devices, and corporate infrastructure telemetry.
• Employ adversary emulation techniques to create test events for detections.
• Transform hunt discoveries into sustainable detections, documentation, and backlog items.
• Engage in the incident response rotation for the initial 6–12 months.
• Assess, scope, contain, and investigate security incidents from the first alert through to resolution.
• Conduct retrospectives and convert insights into detections, playbook enhancements, and visibility improvements.
• Draft and maintain incident response runbooks.
• Oversee the health of security log flows, including onboarding sources, parsing, normalization, and data quality monitoring.
• Develop and sustain Cribl Stream data pipelines to route, enrich, and streamline telemetry before SIEM ingestion.
• Maintain CI/CD and automation processes for the detection program, incorporating GitHub Actions, SIEM API integrations, and AI-assisted gap analysis and pull request evaluations.
• Create processes, standards, and tools that enhance the team's operational effectiveness.
• Mentor colleagues through code reviews, collaborative work, and documentation efforts.
• Partner with IT, Infrastructure, Engineering, and GRC teams to enhance visibility and detection coverage.
• Report directly to the Sr. Director of Security Engineering and Operations under the CISO.
• A minimum of 5 years in security operations, with substantial hands-on experience in detection engineering, threat hunting, or incident response.
• Proven ability to write and manage detections as code within a modern SIEM environment.
• Proficient in Python and comfortable with Git-based workflows, code reviews, and CI/CD practices.
• Strong skills in KQL for crafting detection queries.
• Familiarity with MITRE ATT&CK and conducting coverage analysis.
• Experience in investigating incidents within cloud environments (AWS, GCP, and/or Azure), SaaS platforms, and identity providers.
• Practical knowledge of log pipelines, including data ingestion, parsing, and troubleshooting.
• Ability to differentiate genuine signals from noise and know when to escalate issues.
• Excellent technical and non-technical writing skills for incident summaries, runbooks, and detection documentation.
• Regular use of AI in engineering tasks, with specific examples of its influence on development, testing, or investigations.
• Bonus: Familiarity with Cribl Stream or similar telemetry pipeline tools.
• Bonus: Experience with Sigma rules, adversary emulation (such as Atomic Red Team, Caldera, or comparable), or purple teaming.
• Bonus: Experience in developing agentic or AI-assisted workflows for security operations.
• Bonus: Relevant certifications such as GCIH, GCDA, or equivalent experience.
• Availability for stand-by, on-call, or off-hours support.
• Health insurance
• Dental insurance
• Vision insurance
• Short-term disability insurance
• Life insurance
• Paid holidays
• Paid time off
• Fertility treatment benefit
• 401(k)
• Equity
• Cribl Corporate Bonus Program
Muon Space
Anduril Industries
Siemens Healthineers
Get handpicked remote jobs straight to your inbox weekly.