Sr. Detection Engineer
HybridBengaluru, Karnataka, India
Job Summary
Onboard log sources into the SIEM by parsing, normalizing, and validating telemetry from discovery through production. Architect end-to-end security data pipelines that collect, transform, enrich, and route logs at scale using Terraform, CI/CD, and Python. Transform data in-flight to filter noise, enrich events with context, and route logs to the SIEM or data lake. Build automation for operational workflows, health checks, and alerting integrations while implementing observability to monitor disruptions and data quality. Collaborate with detection engineers to ensure data freshness and accuracy, then design high-fidelity threat detections based on attacker TTPs. Contribute to operational excellence by documenting architecture and participating in on-call rotation.
Required Qualifications
- 8+ years in cybersecurity, SRE, data engineering, or a related field
- at least 2 years focused on security data pipelines or SIEM platform engineering
- Hands-on experience onboarding log sources into a SIEM
- Experience designing and operating security data pipelines
- Experience with data engine/stream processing tooling for filtering, normalizing, enriching, and routing logs
- Experience with Infrastructure-as-Code - Terraform for managing cloud resources
- Experience with DevOps fundamentals - git flow, pull request workflows, CI/CD pipelines
- Experience in software development with Python or Go
- Experience implementing observability and reliability checks for data pipelines
- Experience with cloud-native logging and monitoring services
- Experience with security log types and their value network, endpoint, identity, cloud audit, application
- Experience querying and analyzing logs in a SIEM
Desired Qualifications
- Familiarity with Detection-as-Code practices and how pipeline changes impact downstream detection logic
- Experience with data engine platforms to perform log filtering, normalization, enrichment, and routing
- Background in SRE or platform engineering with an interest in security
- Exposure to the MITRE ATT&CK framework and how data source coverage maps to detection coverage
- Bachelor's degree or equivalent experience in Computer Science, Engineering, or a related field
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.