Security Engineer - Detection & Response
$130,000–$200,000 year
Remote · Phoenix, Arizona, United States or United States
Phoenix, Arizona, United States or United StatesRemoteFull Time$130,000–$200,000 yearSenior LevelNot SpecifiedUnknown
Type
Full Time
Level
Senior Level
Education
Not Specified
Company size
Unknown
Job Summary
Join the AI-powered Security Engineer team at Nerdy, focusing on threat detection and response as part of a cloud-first SaaS company. The role is platform engineering driven, leveraging Python and AI to create scalable systems for detecting threats and automating responses, requiring 5+ years of experience in security engineering and familiarity with frameworks like MITRE.
Required Qualifications
- 5+ years in security engineering, detection engineering, or threat-focused automation roles.
- Strong knowledge of MITRE ATT&CK framework, detection logic, and IOC/IOA patterns.
- Familiarity with MITRE D3FEND for defense-in-depth and response playbook design.
- Hands-on experience designing, deploying, or managing SIEM platforms (vendor-neutral mindset preferred).
- Strong Python scripting skills for integrations, enrichment logic, and playbook development.
- Experience working with structured data formats such as JSON, YAML, logs, and metrics.
- Familiarity with SaaS logging constraints and cloud-native telemetry, preferably AWS.
- Understanding of event-driven architecture and API-driven integrations.
- Demonstrated ability to use AI tools to accelerate scripting, generate or translate detection rules, or assist with enrichment workflows, always with human validation for accuracy.
- Comfortable working autonomously and cross-functionally to deliver reliable detection outcomes.
Desired Qualifications
- Experience building or maintaining detection pipelines using Elastic, Panther, or similar platforms.
- Experience with detection-as-code practices, managing detection logic as version-controlled code with testing and CI/CD.
- Experience writing detection rules in formats such as Sigma, including contributing to open-source or internal detection libraries.
- Experience with MITRE frameworks: ATT&CK (adversary techniques), D3FEND (defensive techniques), and ATLAS (AI-related attacks).
- Experience with OWASP guidance on application telemetry and detection (e.g., AppSensor, Logging Cheat Sheet).
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.