Detection Engineer
Core
Designing and implementing security detection initiatives, tuning detection logic for SIEM and network security platforms, and bridging network engineering with cybersecurity to maximize security device capabilities.
Role type
Senior IC detection engineer (cyber incident response)
Builds
Security detection sets, KQL queries, and detection logic for Microsoft Sentinel and Cisco FirePower/IDS/IPS
Domain
Cybersecurity / Information Security / US Federal Government
Deliverable
production ML models | product features | dashboards & analysis
Required skills
SIEM event and log analysis, KQL query writing, detection logic design and tuning, network security platform configuration, packet and malware analysis, Git/GitHub version control, scripting (PowerShell, Python, regex), TCP/IP and application layer protocols, MITRE ATT&CK framework
Preferred skills
Threat hunting, automation, cloud security monitoring (Azure, AWS), GIAC GCIA/GCED or Microsoft Security Operations Analyst Associate certifications
Technologies
Microsoft Sentinel, KQL, Cisco FirePower, IDS/IPS, Wireshark, Git, GitHub, PowerShell, Python, regex
Responsibilities
Design and implement security detection initiatives; Develop new detection logic for SIEM and network security platforms; Write and optimize KQL queries for Sentinel; Tune detection sets to raise security-relevant events; Maintain version control of detection logic using Git and GitHub; Bridge the gap between network engineering and cybersecurity teams; Conduct technical briefings on network architecture and detection strategies
Seniority
Senior, hands-on IC