Detection Engineer
Core
Design, develop, and optimize detection capabilities to identify cyber threats at the earliest opportunity, reducing false positives to strengthen security posture.
Role type
Senior Detection Engineer
Builds
High-quality detection logic and rules for SIEM, EDR, and other security platforms
Domain
Cybersecurity / Threat Detection
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM platforms (Splunk, Sentinel, QRadar), EDR/XDR tools (CrowdStrike, Defender, Carbon Black), log analysis (Windows, Linux, network, cloud), detection-as-code, MITRE ATT&CK framework, query languages (KQL, SPL, SQL), incident response support, gap analysis
Preferred skills
Python, PowerShell, Bash scripting, cloud security monitoring (AWS, Azure, GCP), detection engineering methodologies, CISSP/GCIA/GCDA/GSOC/GCIH certifications
Technologies
Splunk, Sentinel, QRadar, CrowdStrike, Defender, Carbon Black, AWS, Azure, GCP, MITRE ATT&CK
Responsibilities
Design, develop, and maintain detection rules and use cases across SIEM, EDR, and other security platforms; Analyse logs and telemetry to identify suspicious activity and detection opportunities; Continuously improve detection coverage based on emerging threats and intelligence; Tune and optimise alerts to reduce false positives and improve signal quality; Collaborate with security operations analysts to validate and refine detection logic; Translate threat intelligence into actionable detection rules and analytics; Develop and maintain detection-as-code practices, including version control and testing; Support incident response by enhancing visibility and creating rapid detections; Map detections to frameworks such as MITRE ATT&CK to ensure coverage; Conduct gap analysis and recommend improvements to monitoring capabilities
Seniority
Senior, hands-on IC