> Markdown version of [/jobs/ext/3568805-cyber-operate-detection-engineer-consultant](https://www.wearedevelopers.com/jobs/ext/3568805-cyber-operate-detection-engineer-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Operate Detection Engineer - Consultant - **Company:** Deloitte T.T.L. - **Location:** Austin, TX, United States - **Experience:** Experienced - **Salary:** $82,600.0 - $162,800.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, CompTIA Security+, Cyber Security, Computer Networks, Computer Engineering, Continuous Delivery, Continuous Integration, Query Languages, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Kusto Query Language, Security Information and Event Management, SQL Databases, Scripting, Google Cloud, Cyber Threat Analysis, Git, Information Technology, Cybercrime, Microsoft Sentinel, Splunk, Software Version Control - **Published:** October 3, 2026 - **Apply:** https://dejobs.org/x/x/B2ECD5CE0C7747C2B065812EDA30CE9E/job/ ## About the Role * Ability to work independently and collaborate as part of a team * Effective written and verbal communication skills * Meticulous attention to detail and quality of work product * Ability to build and sustain professional relationships * Ability to lead projects or workstreams * Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment * Strong interpersonal skills and professional demeanor * Ability to meet deadlines * Ability to provide clear guidance to others, * Bachelor's degree in Computer Science, Information Technology, or Computer Engineering. * 2+ years of experience in cybersecurity, security operations, threat intelligence, networking, or systems administration. * Experience reviewing or analyzing authentication events, network traffic, operating system activity, vulnerability data, security logs, or alerts. * Experience using at least one scripting or query language: Python, PowerShell, Structured Query Language (SQL), Kusto Query Language (KQL), or Splunk Processing Language (SPL). * Experience documenting technical findings, test results, configuration changes, or detection logic. * Limited immigration sponsorship may be available. Preferred: * Hands-on experience in a security operations center, with security information and event management or endpoint detection and response platforms, or in threat hunting, incident response, or detection engineering. * Experience using Microsoft Sentinel, Splunk, Google Security Operations, Elastic, CrowdStrike, or Microsoft Defender. * Experience creating or modifying Sigma rules, YARA rules, Suricata signatures, Kusto Query Language queries, or Splunk Processing Language queries. * Experience using Amazon Web Services, Microsoft Azure, or Google Cloud. * Experience using Git, version control systems, detection-as-code practices, or continuous integration/continuous delivery processes. * CompTIA Security+, CompTIA Cybersecurity Analyst (CySA+), or Global Information Assurance Certification (GIAC) Foundational Cybersecurity Technologies certification. ## Description As a Managed Services Engineer II on the Cyber Operate Offering team, you will be responsible for helping develop, test, tune, and maintain cybersecurity detections that support client security operations. * Review threat intelligence, emerging threats, attack techniques, vulnerabilities, and historical incident information to identify detection requirements. * Develop, maintain, and update detection rules, queries, signatures, and indicators of compromise for security monitoring platforms. * Configure and tune detections; identify false positives; and recommend improvements that maintain effective threat coverage. * Test and validate detection rules against known threats and attack scenarios; document test results, configuration changes, and detection logic. * Monitor detection performance; investigate gaps or unexpected results; support incident-response research; and collaborate with security operations center analysts, threat hunters, incident responders, Platform Operations Engineers, and client cybersecurity teams. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)