Senior Security Engineer - Threat Intelligence & Detection Engineering (Hybrid - Seattle)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Experteer Overview As Senior Security Engineer on the TIDE team, you design and operationalize high-fidelity detection and threat-hunting capabilities. You will bridge threat intelligence, MITRE-aligned detection, and automated tooling to protect retail and e-commerce environments. You lead technical work with long horizons, collaborating across SOC, CSIRT, IAM, and Platform teams. You’ll shape detection content, run hunts, and build automation to reduce analyst toil and accelerate incident response. This role offers a meaningful chance to impact security at scale in a fast-paced retail setting. Compensation / Benefits * Design, develop, and maintain detection rules across endpoint, email, identity, network, and cloud domains (CrowdStrike NG-SIEM) * Operationalize the detection lifecycle: threat modeling, testing, deployment, tuning, retirement * Translate threat intel and post-mortems into durable detection logic * Build detection content aligned to MITRE ATT&CK and internal priorities * Collaborate with CSIRT and SOC to enrich investigations with adversary context * Design and execute hypothesis-driven threat hunts; document outcomes and feed patterns back into detection * Provide technical escalation support during complex incidents * Develop and maintain investigation runbooks and analyst guidance * Build and maintain automation to speed detection deployment, alert triage, and threat intel processing * Develop integrations between SIEM, EDR, email security, SOAR, and threat intel platforms * Apply scripting (Python/PowerShell) for automation, log parsing, and IOC ingestion * Mentor junior team members and participate in cross-functional initiatives Tasks * 4+ years of professional experience in detection engineering, threat intelligence, SOC/IR, threat hunting, or security automation * Proficiency in writing detection logic in an enterprise SIEM/XDR; CrowdStrike NG-SIEM (LogScale/CQL) preferred * Working knowledge of MITRE ATT&CK at technique and sub-technique level * Hands-on experience with EDR analysis, behavioral anomaly detection, and post-exploitation investigations * Hands-on experience with hypothesis-driven threat hunting and end-to-end hunt execution * Scripting proficiency in Python and/or PowerShell * Experience contributing to incident response for malware, identity-based attacks, or insider threats * Strong written communication for documentation, detection rationale, and intelligence products * Bachelor’s degree in CS/Info Security or equivalent experience Key requirements * Medical/Vision, Dental * Retirement plan * PTO and Holidays * Life Insurance and Disability * Merchandise Discount and EAP Resources * 401k options
Requirements
to * Collaborate with CSIRT and SOC to enrich investigations with adversary context * Design and execute hypothesis-driven threat hunts; document outcomes and feed patterns back into detection * Provide technical escalation support during complex incidents * Develop and maintain investigation runbooks and analyst guidance * Build and maintain automation to speed detection deployment, alert triage, and threat intel processing * Develop integrations between SIEM, EDR, email security, SOAR, and threat intel platforms * Apply scripting (Python/PowerShell) for automation, log parsing, and IOC ingestion * Mentor junior team members and participate in cross-functional initiatives Tasks * 4+ years of professional experience in detection engineering, threat intelligence, SOC/IR, threat hunting, or security automation * Proficiency in writing detection logic in an enterprise SIEM/XDR; CrowdStrike NG-SIEM (LogScale/CQL) preferred * Working knowledge of MITRE ATT&CK at technique and sub-technique aaa
-
- Hands-on experience with EDR analysis, behavioral anomaly detection, and post-exploitation investigations * Hands-on experience with hypothesis-driven threat hunting and end-to-end hunt execution * Scripting proficiency in Python and/or PowerShell * Experience contributing to incident response for malware, identity-based attacks, or insider threats * Strong written communication for documentation, detection rationale, and intelligence products * Bachelor’s degree in CS/Info Security or equivalent experience Key requirements * Medical/Vision, Dental * Retirement plan * PTO and Holidays * Life Insurance and Disability * Merchandise Discount and EAP Resources * 401k options
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Walking Into The Era of Supply Chain Risks
The Overflow: Security and Privacy