Threat Detection Engineer – Security Operations
Core
Develop, test, and optimize high-fidelity security detections across modern data platforms, focusing on security analytics, automation, and threat detection at scale, with a specific emphasis on AI-specific attack surfaces.
Role type
Threat Detection Engineer (Security Operations)
Builds
Scalable detection rules, analytics, anomaly models, and AI-augmented detection pipelines for cloud and enterprise environments.
Domain
Cybersecurity / AI Security / Cloud Security
Deliverable
production ML models | product features
Required skills
Python, SQL, Splunk, Elastic Stack, Google Chronicle, YARA-L, Sigma, MITRE ATT&CK, Infrastructure-as-Code (IaC), LLM APIs, Prompt Engineering, Anomaly Detection, Embedding Models
Preferred skills
GCP, GKE, SOAR integrations, Agentic AI frameworks (LangChain, LlamaIndex), Snowflake, Red teaming, Adversarial testing
Technologies
Splunk, Google Chronicle, Elastic/Logstash, Python, YAML, Terraform, GitOps, Snowflake, SQL, OpenAI, Anthropic, Google Gemini, LangChain, LlamaIndex
Responsibilities
Design and implement detection logic across SIEM/SOAR platforms; Build scalable detection rules and anomaly models aligned with MITRE ATT&CK; Develop detection-as-code using Python and YAML-based formats; Design and evaluate LLM-assisted detection and triage workflows; Build AI-augmented detection pipelines for anomaly scoring and log analysis; Identify and detect AI-specific threats like prompt injection and model abuse; Perform quality assurance and validation of alerts; Leverage Snowflake and SQL to query large telemetry datasets; Contribute to IaC workflows for detection deployment; Collaborate with Threat Intelligence and IR teams; Participate in detection tuning, red/blue team exercises, and post-incident reviews; Maintain 24x7 on-call rotation.
Seniority
Mid-level (2-4 years experience), hands-on IC