> Markdown version of [/jobs/ext/2715026-security-engineer-detection-engineering](https://www.wearedevelopers.com/jobs/ext/2715026-security-engineer-detection-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Detection Engineering - **Company:** Saronic Technologies - **Location:** Austin, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Build Automation, Automation of Tests, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Information Engineering, Extract Transform Load (ETL), Query Languages, Linux on Embedded Systems, Emulators, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Kusto Query Language, Security Information and Event Management, Data Logging, Data Ingestion, Software Security, Mitre Att&ck, Indexer, Infrastructure Automation Frameworks, Cybercrime, Performance Monitor, Software Coding, Terraform, Data Pipelines, Security Orchestration, Automation & Response, Golang - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-detection-engineering-saronic-technologies-8289172 ## About the Role * 3+ years of hands-on experience in detection engineering, security operations, security automation, or a closely related security engineering role * Demonstrated experience designing, testing, and tuning detection rules and analytic queries across production security telemetry (endpoint, cloud, network, identity, or DLP) * Hands-on experience with SIEM platforms and proficiency with query languages such as SPL, KQL, or equivalent * Experience building and operating security data pipelines, including log ingestion, normalization, enrichment, and data quality management * Understanding of data engineering concepts including ETL pipelines, data modeling, schema design, and indexing as applied to security telemetry * Hands-on coding experience in Python, PowerShell, Go, or Rust for security automation, detection tooling, or pipeline development, and familiarity with Terraform for managing detection and logging infrastructure as code * Understanding of MITRE ATT&CK framework and its application to detection coverage and gap analysis * Ability to obtain and maintain a security clearance, * Experience in defense, aerospace, robotics, autonomy, or other high-assurance environments * Experience with EDR platforms including custom detection rule creation and telemetry analysis * Experience with cloud-native detection in AWS and Microsoft 365/Azure * Experience using Terraform to deploy and manage security monitoring infrastructure, log pipeline components, or cloud-native security service configurations * Hands-on experience with incident response, threat hunting, or adversary emulation * Exposure to embedded Linux, operational technology, or ICS telemetry and detection * Familiarity with NIST SP 800-171, NIST SP 800-53, or CMMC and their logging and monitoring requirements * Relevant certifications such as GCIH, GCIA, GCDA, GSOM, OSDA, or OSCP ## Description * Design, build, test, and tune high-fidelity detection rules and analytic queries across endpoint, cloud, network, identity, and DLP telemetry sources * Develop and maintain detection content using detection-as-code practices including version-controlled logic, automated testing, and CI/CD deployment * Map detection coverage to MITRE ATT&CK, identify gaps, and prioritize new detection development based on threat intelligence and business risk * Engineer correlation rules, behavioral analytics, and anomaly-based detections that minimize false positives while surfacing real adversary tradecraft * Own the detection lifecycle from initial development through production tuning, performance monitoring, and retirement * Build and operate pipelines to ingest, normalize, enrich, and manage security telemetry at scale across diverse data sources, using Terraform and infrastructure-as-code practices to deploy and maintain logging and detection infrastructure * Design and maintain log collection, parsing, and enrichment configurations that ensure the right telemetry is available at the right fidelity for detection and investigation * Evaluate and onboard new telemetry sources as Saronic's infrastructure and threat landscape evolve * Monitor pipeline health, data quality, and ingestion reliability to ensure detections operate on complete and accurate data * Develop and manage automated response playbooks in SOAR platforms to accelerate containment and reduce analyst toil * Build automation that enriches alerts with contextual data, reducing investigation time and improving analyst decision-making * Support incident response efforts and translate lessons learned into improved detections and playbooks * Partner with SOC analysts, Cloud Security, Product Security, and IT teams to close visibility and detection gaps across environments * Collaborate with threat intelligence to ensure detection engineering is informed by current adversary TTPs relevant to defense, maritime, and autonomous systems ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Optimizing Discovery: PostgreSQL's Role in Transforming GetYourGuide's Search](https://www.wearedevelopers.com/videos/1647-optimizing-discovery-postgresql-s-role-in-transforming-getyourguide-s-search) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)