> Markdown version of [/jobs/ext/1508533-detection-engineer-remote](https://www.wearedevelopers.com/jobs/ext/1508533-detection-engineer-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Detection Engineer - REMOTE - **Company:** Paylocity - **Location:** Houston, TX, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), ARM Architecture, Audit Trail, Cloud Computing Security, Computer Networks, Continuous Integration, Event Logging, Intrusion Detection and Prevention, Java GUIs, Python (Programming Language), Performance Tuning, Red Team (Cyber Security), Kusto Query Language, Security Information and Event Management, YAML, Cloud Platform System, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Git Flow, Cybercrime, Windows Security, Restful APIs, Splunk, SentinelOne Expertise, Software Version Control - **Published:** July 30, 2026 - **Apply:** https://recruiting.paylocity.com/Recruiting/Jobs/Apply/4376240 ## About the Role · 2-5+ years of hands-on experience in detection engineering, threat hunting, or incident response. · Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows. · Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL. · Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs. · Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points. · Ability to quickly learn new security technologies and adapt detection strategies accordingly. · Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm. Preferred · Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus). · Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD). · Exposure to multi-tenant or MDR environments and scaling detections across customer environments. · Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows. · Experience in IR consulting and working across diverse EDR/SIEM stacks. ## Description Binary Defense is seeking an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You'll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments. Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability. Responsibilities · Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne). · Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control. · Leverage APIs to automate rule deployment, validation, and telemetry inspection-reducing reliance on GUIs. · Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors. · Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps. · Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness. · Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting. · Support documentation of detection logic, coverage rationale, and response guidance. · Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why Git Still Matters](https://www.wearedevelopers.com/videos/100288-why-git-still-matters) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Remote Jobs](https://www.wearedevelopers.com/magazine/255-best-paying-remote-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)