Detection Engineer
$100,000–$160,000 year
Remote
Job Summary
Design, build, and maintain high-fidelity detections across cloud, identity, endpoint, and SaaS environments using detection-as-code practices. Leverage AI to author rules, establish behavioral baselines for anomaly detection, and engineer machine-readable outputs for autonomous investigation. Validate logic through attack simulations and test harnesses, then tune false-positive and false-negative rates based on performance data. Translate threat intelligence and SOC findings into durable detection logic while partnering with analysts to close coverage gaps against MITRE ATT&CK. Support customer-specific tuning to adapt content to unique business contexts.
Required Qualifications
- 5+ years of hands-on cybersecurity experience, with significant time in detection engineering
- Proven track record designing, building, and tuning detections at scale across SIEM, EDR, or custom detection platforms
- Strong proficiency in detection languages and formats such as Sigma, KQL, SPL, or YARA-L
- Deep knowledge of attacker tactics, techniques, and procedures (MITRE ATT&CK) and how they manifest in logs across cloud, identity, endpoint, and SaaS telemetry
- Experience with detection-as-code workflows: Git, peer review, automated testing, and CI/CD for detection content
- Experience using AI tools to accelerate detection authoring, tuning, or validation
- Experience building behavioral or anomaly-based detections: establishing baselines of normal activity and engineering detections that flag meaningful deviations
- Strong log-analysis skills and demonstrated ability to distinguish malicious activity from benign noise across diverse data sources
- Clear written and verbal communication — able to document detection logic and explain coverage and trade-offs to engineers, analysts, and customers
Desired Qualifications
- Experience in an MDR, MSSP, or high-volume SOC environment
- Experience with attack simulation and validation frameworks (Atomic Red Team, purple teaming)
- Background in threat hunting or incident response across cloud environments
- Experience with UEBA platforms or statistical/ML-based detection methods (peer grouping, time-series baselining, outlier scoring)
- Experience building AI-assisted detection or investigation tooling from scratch
- Contributions to open-source detection content or the broader detection engineering community
- Python preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.