Specialist, Cyber Detection Engineer
$96,200–$158,800 year
On-siteNewark, New Jersey, United States
Job Summary
Operationalize security alerting and develop custom detection capabilities across endpoint, identity, network, cloud, and application domains. Author and maintain detections using SIEM/XDR platforms, ensuring performance, scalability, and precision. Transform threat intelligence, incident learnings, and hunt findings into new detection content or coverage improvements. Validate detections using realistic attack scenarios, emulation results, and historical data. Identify telemetry gaps and log data quality issues that limit visibility, working with platform teams to remediate. Rapidly develop temporary analytics or scoping queries to support Incident Response efforts during active investigations. Participate in continuous improvement initiatives, metrics, and reporting processes.
Required Qualifications
- 3+ years of experience in detection engineering, incident response, threat hunting, or security operations in large enterprise environments
- Practical experience working with common Endpoint, Identity, Network, Cloud & SaaS technologies, and associated logging
- Proven experience developing detection content across multiple telemetry sources
- Strong proficiency with at least one major SIEM/XDR ecosystem and advanced query authoring
- Solid understanding of adversary tradecraft with practical experience applying MITRE ATT&CK to detection design, validation, and coverage assessment
- Ability to reason about attacker behaviors, detection logic trade-offs, and operational impacts rather than relying solely on static indicators
- Experience using common scripting languages (e.g. Python, PowerShell) and to solve problems, automation tasks and interact with REST/GraphQL APIs
- Strong written and verbal skills, with the ability to communicate effectively with both technical and non-technical stakeholders
Desired Qualifications
- Splunk Power User
- Microsoft SC-200
- AZ-500
- CompTIA Cybersecurity Analyst (CySA+)
- SQL strongly preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.