Artemis Security logo
Artemis SecurityPosted 2 weeks ago

Detection Engineer

$100,000–$160,000 year

Remote

Full TimeSmall

Job Summary

Design, build, and maintain high-fidelity detections across cloud, identity, endpoint, and SaaS environments using detection-as-code practices. Leverage AI to author rules, establish behavioral baselines for anomaly detection, and engineer machine-readable outputs for autonomous investigation. Validate logic through attack simulations and test harnesses, then tune false-positive and false-negative rates based on performance data. Translate threat intelligence and SOC findings into durable detection logic while partnering with analysts to close coverage gaps against MITRE ATT&CK. Support customer-specific tuning to adapt content to unique business contexts.

Required Qualifications

  • 5+ years of hands-on cybersecurity experience, with significant time in detection engineering
  • Proven track record designing, building, and tuning detections at scale across SIEM, EDR, or custom detection platforms
  • Strong proficiency in detection languages and formats such as Sigma, KQL, SPL, or YARA-L
  • Deep knowledge of attacker tactics, techniques, and procedures (MITRE ATT&CK) and how they manifest in logs across cloud, identity, endpoint, and SaaS telemetry
  • Experience with detection-as-code workflows: Git, peer review, automated testing, and CI/CD for detection content
  • Experience using AI tools to accelerate detection authoring, tuning, or validation
  • Experience building behavioral or anomaly-based detections: establishing baselines of normal activity and engineering detections that flag meaningful deviations
  • Strong log-analysis skills and demonstrated ability to distinguish malicious activity from benign noise across diverse data sources
  • Clear written and verbal communication — able to document detection logic and explain coverage and trade-offs to engineers, analysts, and customers

Desired Qualifications

  • Experience in an MDR, MSSP, or high-volume SOC environment
  • Experience with attack simulation and validation frameworks (Atomic Red Team, purple teaming)
  • Background in threat hunting or incident response across cloud environments
  • Experience with UEBA platforms or statistical/ML-based detection methods (peer grouping, time-series baselining, outlier scoring)
  • Experience building AI-assisted detection or investigation tooling from scratch
  • Contributions to open-source detection content or the broader detection engineering community
  • Python preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce