CareerPlanGet AI match score →

Detection Engineer

San Antonio, TX💼 Full-time💰 $91,300–$91,300🗓 2026-06-08 → 2026-07-31

Core

Designing and implementing security detection initiatives, tuning detection logic for SIEM and network security platforms, and bridging network engineering with cybersecurity to maximize security device capabilities.

Role type

Senior IC detection engineer (cyber incident response)

Builds

Security detection sets, KQL queries, and detection logic for Microsoft Sentinel and Cisco FirePower/IDS/IPS

Domain

Cybersecurity / Information Security / US Federal Government

Deliverable

production ML models | product features | dashboards & analysis

Required skills

SIEM event and log analysis, KQL query writing, detection logic design and tuning, network security platform configuration, packet and malware analysis, Git/GitHub version control, scripting (PowerShell, Python, regex), TCP/IP and application layer protocols, MITRE ATT&CK framework

Preferred skills

Threat hunting, automation, cloud security monitoring (Azure, AWS), GIAC GCIA/GCED or Microsoft Security Operations Analyst Associate certifications

Technologies

Microsoft Sentinel, KQL, Cisco FirePower, IDS/IPS, Wireshark, Git, GitHub, PowerShell, Python, regex

Responsibilities

Design and implement security detection initiatives; Develop new detection logic for SIEM and network security platforms; Write and optimize KQL queries for Sentinel; Tune detection sets to raise security-relevant events; Maintain version control of detection logic using Git and GitHub; Bridge the gap between network engineering and cybersecurity teams; Conduct technical briefings on network architecture and detection strategies

Seniority

Senior, hands-on IC

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Greenhouse ↗