Detection Engineer
Core
Design, implement, and validate detection capabilities for CSIRT by building high-fidelity detection logic, conducting regression testing, and executing breach and attack simulations (BAS).
Role type
Senior IC detection engineer (cyber defense)
Builds
Detection rules, signatures, correlation logic, and automated triage playbooks for SIEM and SOAR platforms
Domain
Cybersecurity / Threat Detection / Incident Response
Deliverable
production ML models | product features
Required skills
SIEM platforms (Splunk, Sentinel), detection engineering, log parsing, data normalization, Python/PowerShell scripting, SOAR platforms, cloud security telemetry (AWS/Azure/GCP/Aliyun), MITRE ATT&CK frameworks, adversary simulation tools (AttackIQ, Caldera), containerized security (Kubernetes, serverless)
Preferred skills
Artificial intelligence/machine learning concepts applied to cybersecurity, purple team exercises, modern application environments
Responsibilities
Develop, test, and maintain detection rules and correlation logic; Conduct regression testing of detection rules; Perform breach and attack simulations (BAS); Map detection logic to adversary techniques using MITRE ATT&CK; Integrate threat intelligence feeds and IOCs; Tune detection logic to reduce false positives; Automate enrichment and triage via SOAR playbooks; Contribute to SOC metrics including detection coverage and false positive ratios
Seniority
Mid-level, hands-on IC