Detection Engineer - Security Operations
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+17 more
Job description
Our client is seeking an experienced Detection Engineer to support security operations by designing, building, and tuning detection capabilities across multiple security platforms.
This role will focus on improving detection coverage, reducing false positives, building security automation and orchestration, and partnering closely with Incident Response, DFIR, Insider Risk, and Detection Platform Engineering teams. The Detection Engineer will also support incident response playbooks and help integrate detections into ServiceNow Security Incident Response (SIR) workflows.
Responsibilities
- Design, build, and tune detection rules and correlation logic across:
- Splunk
- CrowdStrike NG-SIEM / LogScale
- Zscaler
- Onyx Security
- Reduce false-positive rates and identify and close detection coverage gaps.
- Build and maintain API- and AWS Lambda-based orchestration pipelines.
- Route alerts from detection platforms into ServiceNow Security Incident Response (SIR).
- Enrich alerts with relevant context before they reach incident responders.
- Partner with Detection Platform Engineering to align new detections with:
- Existing data models
- Data ingestion pipelines
- Broader detection roadmaps
- Work directly with Incident Responders, DFIR, and Insider Risk teams to identify investigative gaps and translate them into new or refined detection logic.
- Support development of incident response playbooks.
- Partner with responders to define and document:
- Triage steps
- Escalation criteria
- Containment actions
- Incorporate response processes into ServiceNow SIR workflows and SOAR-style automation.
- Validate detections against live test data and known Tactics, Techniques, and Procedures (TTPs).
- Document detection tuning decisions and false-positive rationale for audit and handoff.
- Participate in post-incident lessons-learned reviews.
- Convert incident findings into detection or playbook improvements.
- Maintain detection-as-code practices, including:
- Version control
- Peer review
- Change documentation
- Maintain documentation for all production detection logic.
Requirements
- 4-7 years of total Security Engineering and/or Detection Engineering experience.
- At least 2 years of multi-platform detection engineering experience, rather than experience limited to a single security tool.
- Hands-on detection engineering experience with Splunk (SPL).
- Hands-on experience with CrowdStrike NG-SIEM / LogScale (CQL), including:
- Multi-source joins
- Working knowledge of Zscaler logging and building detections using:
- Proxy telemetry
- DNS telemetry
- SSL telemetry
- Practical experience with API-based integrations and AWS Lambda for security automation and orchestration.
- Experience using automation for alert routing, enrichment, and/or automated response.
- Experience with ServiceNow Security Incident Response (SIR), including:
- Case creation via API
- Field mapping
- Workflow logic
- Familiarity with MITRE ATT&CK and translating adversary behaviors into detection logic.
- Scripting proficiency, preferably Python, for automation and API integrations.
- Strong cross-functional communication skills with the ability to work directly with Incident Response analysts and Platform Engineers., * Exposure to AI agent security/governance platforms, such as Onyx Security, or the ability to quickly learn the platform.
- Experience with SOAR platforms such as:
- Splunk SOAR
- Palo Alto XSOAR
- Tines
- Similar platforms
- Experience building or supporting Incident Response playbooks and runbooks within a live SOC.
- Familiarity with UEBA or Insider Risk detection concepts.
- Cloud security monitoring experience across:
- AWS
- Azure
- GCP
- Relevant certifications are a plus, including:
- GCIA
- GCDA
- CrowdStrike CCFA/CCFR
- Splunk Certified Power User/Admin
- AWS Security certifications
Education
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent hands-on experience.
- 4+ years of relevant hands-on experience in lieu of a degree is acceptable.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Is Software Engineering Over-Saturated?
Dev Digest 134 - Where pixels sing?
Fully Remote Software Engineer Jobs
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.