Detection Engineer - Security Operations

Catapult Solutions Group
United States
4 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$176,155.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Domain Name System (DNS) Intrusion Detection and Prevention Python (Programming Language) OnyX for Mac Runbook Security Information and Event Management Systems Integration
+17 more
Test Data Data Logging Scripting Transport Layer Security Mitre Att&ck AWS Lambda Information Technology Cortex XSOAR Platform Virtual Agents Api Design Splunk Multiplatform Software Version Control Data Pipelines Api Management Security Orchestration, Automation & Response Servicenow

Job description

Our client is seeking an experienced Detection Engineer to support security operations by designing, building, and tuning detection capabilities across multiple security platforms.

This role will focus on improving detection coverage, reducing false positives, building security automation and orchestration, and partnering closely with Incident Response, DFIR, Insider Risk, and Detection Platform Engineering teams. The Detection Engineer will also support incident response playbooks and help integrate detections into ServiceNow Security Incident Response (SIR) workflows.

Responsibilities

  • Design, build, and tune detection rules and correlation logic across:
  • Splunk
  • CrowdStrike NG-SIEM / LogScale
  • Zscaler
  • Onyx Security
  • Reduce false-positive rates and identify and close detection coverage gaps.
  • Build and maintain API- and AWS Lambda-based orchestration pipelines.
  • Route alerts from detection platforms into ServiceNow Security Incident Response (SIR).
  • Enrich alerts with relevant context before they reach incident responders.
  • Partner with Detection Platform Engineering to align new detections with:
  • Existing data models
  • Data ingestion pipelines
  • Broader detection roadmaps
  • Work directly with Incident Responders, DFIR, and Insider Risk teams to identify investigative gaps and translate them into new or refined detection logic.
  • Support development of incident response playbooks.
  • Partner with responders to define and document:
  • Triage steps
  • Escalation criteria
  • Containment actions
  • Incorporate response processes into ServiceNow SIR workflows and SOAR-style automation.
  • Validate detections against live test data and known Tactics, Techniques, and Procedures (TTPs).
  • Document detection tuning decisions and false-positive rationale for audit and handoff.
  • Participate in post-incident lessons-learned reviews.
  • Convert incident findings into detection or playbook improvements.
  • Maintain detection-as-code practices, including:
  • Version control
  • Peer review
  • Change documentation
  • Maintain documentation for all production detection logic.

Requirements

  • 4-7 years of total Security Engineering and/or Detection Engineering experience.
  • At least 2 years of multi-platform detection engineering experience, rather than experience limited to a single security tool.
  • Hands-on detection engineering experience with Splunk (SPL).
  • Hands-on experience with CrowdStrike NG-SIEM / LogScale (CQL), including:
  • Multi-source joins
  • Working knowledge of Zscaler logging and building detections using:
  • Proxy telemetry
  • DNS telemetry
  • SSL telemetry
  • Practical experience with API-based integrations and AWS Lambda for security automation and orchestration.
  • Experience using automation for alert routing, enrichment, and/or automated response.
  • Experience with ServiceNow Security Incident Response (SIR), including:
  • Case creation via API
  • Field mapping
  • Workflow logic
  • Familiarity with MITRE ATT&CK and translating adversary behaviors into detection logic.
  • Scripting proficiency, preferably Python, for automation and API integrations.
  • Strong cross-functional communication skills with the ability to work directly with Incident Response analysts and Platform Engineers., * Exposure to AI agent security/governance platforms, such as Onyx Security, or the ability to quickly learn the platform.
  • Experience with SOAR platforms such as:
  • Splunk SOAR
  • Palo Alto XSOAR
  • Tines
  • Similar platforms
  • Experience building or supporting Incident Response playbooks and runbooks within a live SOC.
  • Familiarity with UEBA or Insider Risk detection concepts.
  • Cloud security monitoring experience across:
  • AWS
  • Azure
  • GCP
  • Relevant certifications are a plus, including:
  • GCIA
  • GCDA
  • CrowdStrike CCFA/CCFR
  • Splunk Certified Power User/Admin
  • AWS Security certifications

Education

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent hands-on experience.
  • 4+ years of relevant hands-on experience in lieu of a degree is acceptable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all