
Senior Threat Detection & Response Engineer
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in United States.
• Define, design, and construct AI/ML pipelines for investigation, triage, enrichment, and generation of detections.
• Take ownership of AI-assisted investigations and triage, starting from data foundations and feature/enrichment pipelines to model selection, evaluation, and secure production deployment.
• Establish standards for validating, explaining, and fostering trust in AI/ML outputs within detection and response workflows.
• Design and manage the detection-as-code pipeline, encompassing repository structure, detection schema, peer reviews, automated testing, and staged CI/CD deployment across SIEM, XDR, and endpoint detection surfaces.
• Define technical standards, reusable patterns, and quality controls for detection content.
• Develop tools and APIs for the creation, testing, and debugging of detections.
• Create AI-driven automation and SOAR-style workflows for phishing, DLP, enrichment, routing, and the closure of verified-benign reports.
• Establish response automation, playbooks, containment actions, and integrations to minimize dwell time and reduce mean time to respond.
• Establish and maintain a baseline for MITRE ATT&CK coverage.
• Collaborate with Threat Intelligence and Threat Hunting to transform findings into resilient, validated detections.
• Implement continuous validation through breach-and-attack simulations and purple-team activities.
• Lead technical projects from inception to completion, including scoping, execution, delivery accountability, and outcome ownership.
• Act as the senior-most individual contributor technical authority and the final technical escalation point for detection engineering.
• Influence the roadmap and tooling decisions in collaboration with internal platform partners and contribute to shaping a global follow-the-sun operating model.
• Hands-on experience in designing and constructing AI/ML pipelines for security data, including data and enrichment foundations, model evaluation, production deployment, and guardrails.
• Experience in writing, versioning, testing, and deploying detections as code.
• Profound hands-on detection engineering experience across SIEM and EDR/XDR platforms.
• Proficiency in KQL, SQL, Sigma, or similar languages.
• Strong scripting and development skills, such as Python or Go.
• Experience in mapping detections to MITRE ATT&CK and collaborating with threat hunting and threat intelligence teams.
• Proven track record of leading technical projects to completion and owning delivery outcomes.
• Capability to articulate detection strategies, AI/ML design decisions, and engineering trade-offs to both engineers and senior leadership.
• Background investigation is required.
• Allstate typically does not sponsor individuals for employment-based visas for this position.
• A dedicated, private workspace free from distractions when working from home.
• Reliable internet connection with minimum speeds of 50 MB download and 5 MB upload.
• Nice to have: Experience in AI-assisted/agentic SOC; security data engineering or streaming pipeline experience; enterprise SIEM, XDR, and EDR experience; purple-team, adversary-emulation, or breach-and-attack-simulation experience; exposure to financial services, insurance, or regulated, high-scale environments.
• Comprehensive technology setup, which includes a laptop, monitors, headset, keyboard, and mouse.
• Monthly connectivity reimbursement for employees eligible to work from home.
ePlus Technology Solutions
Thurra
IFS
Get handpicked remote jobs straight to your inbox weekly.