Security Spec Lead

American Electric Power
Austin, TX, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$18,720.0 - $41,600.0
Working hours
Regular working hours
Job source

Tech stack

Data Analysis Cyber Security Intrusion Detection and Prevention Network Intrusion Detection Systems Reverse Engineering Security Information and Event Management Mitre Att&ck Malware Cyber Threat Analysis Information Technology Cybercrime Purple Team (Cyber Security)

Job description

We are seeking a highly motivated Detection Engineer to join our Cybersecurity Intelligence and Defense team. The Detection Engineer will be responsible for designing, developing, tuning, and maintaining threat detection capabilities across enterprise environments. This role works closely with Threat Intelligence Analysts, Threat Hunters, Incident Responders, and Security Operations Center (SOC) personnel to identify emerging threats and improve the organization’s ability to detect malicious activity., The ideal candidate possesses a strong understanding of adversary tactics, techniques, and procedures (TTPs), security monitoring technologies, and data analysis. This individual will play a critical role in advancing detection coverage, reducing false positives, and improving overall cyber resilience., * Design, develop, test, and deploy security detections across SIEM, EDR, NDR, cloud, and other security platforms.

  • Translate threat intelligence and threat hunting findings into actionable detection content.
  • Create and maintain detection rules, correlation searches, behavioral analytics, and alerting mechanisms.
  • Tune existing detections to improve fidelity and reduce alert fatigue.
  • Map detections to the MITRE ATT&CK framework and identify coverage gaps.
  • Collaborate with Threat Hunting and Incident Response teams to improve detection effectiveness.
  • Develop use cases and detection strategies for emerging threats and adversary behaviors.
  • Analyze security telemetry from endpoints, networks, cloud environments, and identity providers.
  • Measure and report on detection performance, effectiveness, and coverage.
  • Support purple team exercises, tabletop exercises, and adversary emulation activities.
  • Maintain documentation, detection standards, and engineering processes.
  • Automate detection engineering workflows where appropriate.

Requirements

Licenses and Certifications: CSFA, GCCC, GCDA, GCED, GCFA, GCFE, GCIA, GCIH, GCIP, GCTI, GDAT, GICSP, GMON, GOSI, GREM, GRID, GSOM, GXPN, OSCP, OSEE, Treadstone Certified Threat Intelligence Analyst/Certified Threat Counterintelligence Analyst, CERT Incident Response Process Professional, CREST Certified Host Intrusion Analyst, CREST Certified Incident manager, CREST Certified malware Reverse Engineer, CREST Certified Network Intrusion Analyst, CREST Certified Threat Intelligence Manager

Experience: Demonstrable experience in one or more of the following disciplines:

  • Detection Engineer
  • Incident Response Analyst
  • CIRC/SOC Lead
  • Threat Intelligence or Counterintelligence Analyst
  • Cyber Threat Hunt Analyst
  • Malware Reverse Engineer
  • Clearance: Current government security clearance or ability to obtain a security clearance at a minimum of the Secret level.

What We’re Looking For:

Education requirements are listed below:

  • Bachelor’s degree OR Associates degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) or NERC CIP compliance; OR High School Diploma/GED with 4 years relevant experience in IT system administration/help desk/security (cyber or physical); OR graduation from an approved Cyber Security Program; alternatively, may have non-degree qualifications (such as hands-on demonstrated ability in a technical interview/assessment).

Work Experience requirement listed below:

  • 7 or more years of Information Technology related experience; OR 5 or more years of security related experience, which may include military/government work experience in addition to any experience identified above; OR NERC-CIP compliance in addition to any experience identified above.

About the company

At AEP, we’re more than just an energy company - we’re a team of dedicated professionals committed to delivering safe, reliable, and innovative energy solutions. Guided by our mission to put the customer first, we strive to exceed expectations by listening, responding, and continuously improving the way we serve our communities. If you’re passionate about making a meaningful impact and being part of a forward-thinking organization, this is the company for you!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all