Lead Detection Engineer
Core
Setting direction for detection engineering standards, tooling, and automation to operationalize security detections across endpoint, identity, cloud, and infrastructure.
Role type
Lead Detection Engineer (Individual Contributor)
Builds
Detection-as-Code pipelines, high-fidelity behavioral detections, and automated response workflows connecting to SIEM/EDR platforms.
Domain
Cybersecurity / Security Operations / Threat Detection
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Detection coverage strategy, Detection-as-Code workflows, SIEM/EDR platform expertise, query development (SPL/KQL/Sigma), MITRE ATT&CK framework, threat intelligence translation, behavioral detection design, CI/CD practices, technical standards definition, detection quality metrics.
Preferred skills
Offensive security background, threat hunting, SOAR playbook design, cloud security (Azure/AWS/GCP), AI-assisted detection workflows.
Technologies
Splunk, Microsoft Sentinel, CrowdStrike, Git, CI/CD, MITRE ATT&CK, SIEM, EDR, Azure, AWS, GCP.
Responsibilities
Define detection coverage strategy across endpoint, identity, cloud, and infrastructure; build Detection-as-Code pipelines with version control and testing; design architecture connecting detections to enrichment and automated response; establish technical standards for detection lifecycle; measure and improve detection quality and fidelity; design high-fidelity behavioral detections for SIEM and EDR; research attacker techniques and translate threat intelligence into scalable detections; validate detections via threat simulations; partner with SOC analysts to close feedback loops; define and track detection engineering metrics.
Seniority
Lead, hands-on IC with strategic ownership