Senior Detection Engineer (SIEM / Security Observability)
Core
Build and operate detection and telemetry capabilities for security visibility across production and corporate environments in a cloud-native setting.
Role type
Senior IC detection engineer (SIEM / security observability)
Builds
Detection rules, alerting workflows, log ingestion pipelines, and dashboards for security operations
Domain
Cybersecurity, cloud-native infrastructure, security observability
Deliverable
production ML models | product features | dashboards & analysis
Required skills
SIEM engineering, detection rule development, log parsing and normalization, cloud infrastructure knowledge, Python/PowerShell scripting, MITRE ATT&CK framework, security telemetry analysis, alert tuning, correlation logic
Preferred skills
Datadog Cloud SIEM, SentinelOne, Wiz, SOAR, detection-as-code frameworks (Sigma), zero-trust architectures, privileged access management
Technologies
Datadog, SentinelOne, Wiz, Splunk, Microsoft Sentinel, Elastic, AWS
Responsibilities
Design and maintain detection/telemetry capabilities across security platforms; develop and tune high-fidelity detection rules; improve alert quality by reducing false positives; implement detection-as-code practices; define logging and telemetry standards; build and optimize log ingestion pipelines; automate onboarding of new data sources; correlate signals across security tooling; partner with Security Operations to improve triage workflows; build dashboards for operational decision-making; map detection coverage against MITRE ATT&CK.
Seniority
Senior, hands-on IC