CareerPlanSign in

Detection Engineer

Best💼 Full-time💰 $61,200–$61,200🗓 2026-09-08 → 2026-09-26

Core

Design, implement, and validate detection capabilities for CSIRT by building high-fidelity detection logic, conducting regression testing, and executing breach and attack simulations (BAS).

Role type

Senior IC detection engineer (cyber defense)

Builds

Detection rules, signatures, correlation logic, and automated triage playbooks for SIEM and SOAR platforms

Domain

Cybersecurity / Threat Detection / Incident Response

Deliverable

production ML models | product features

Required skills

SIEM platforms (Splunk, Sentinel), detection engineering, log parsing, data normalization, Python/PowerShell scripting, SOAR platforms, cloud security telemetry (AWS/Azure/GCP/Aliyun), MITRE ATT&CK frameworks, adversary simulation tools (AttackIQ, Caldera), containerized security (Kubernetes, serverless)

Preferred skills

Artificial intelligence/machine learning concepts applied to cybersecurity, purple team exercises, modern application environments

Responsibilities

Develop, test, and maintain detection rules and correlation logic; Conduct regression testing of detection rules; Perform breach and attack simulations (BAS); Map detection logic to adversary techniques using MITRE ATT&CK; Integrate threat intelligence feeds and IOCs; Tune detection logic to reduce false positives; Automate enrichment and triage via SOAR playbooks; Contribute to SOC metrics including detection coverage and false positive ratios

Seniority

Mid-level, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.