Senior Threat Detection Engineer
Core
Design and implement end-to-end automated detection and response for security threats using a Detection-as-Code philosophy, integrating AI/LLM for log analysis and automation.
Role type
Senior Threat Detection Engineer (Security Operations)
Builds
Automated threat detection rules, AI-driven log analysis pipelines, and real-time response playbooks for e-commerce infrastructure.
Domain
Cybersecurity, Threat Intelligence, E-commerce
Deliverable
production ML models | product features
Required skills
Threat modeling, SIEM rule development, Cloud security logging, Network/OS/Application threat analysis, MITRE ATT&CK framework, SQL/Python/SPL query writing, Incident response collaboration
Preferred skills
Detection-as-Code (CI/CD), Python security automation, AI/LLM for security analysis, Threat hunting, Red/Purple teaming, Insider threat detection, Regulatory compliance monitoring
Technologies
SIEM, SQL, Python, SPL, AWS, MITRE ATT&CK, LLM
Responsibilities
Define threat use cases and manage detection coverage based on threat frameworks; Analyze multi-layer logs (network, OS, app, cloud) to implement detection logic in SIEM; Continuously improve detection quality via pre/post-deployment testing and tuning; Design and implement detection for compliance requirements (privacy, financial security); Expand detection systems for advanced threats like ATO and insider threats; Utilize AI/LLM to automate scenario analysis and build knowledge bases; Collaborate with Red Team, Threat Intel, and IR teams to validate scenarios; Document rule lifecycle and manage change history.
Seniority
Senior, hands-on IC