Security Detection Engineer
Core
Designing, developing, and maintaining high-fidelity detection logic across enterprise security platforms to support proactive threat detection and an Autonomic Security Operations model.
Role type
Security Detection Engineer
Builds
Detection rules and logic for SIEM, EDR, NDR, and cloud-native platforms
Domain
Cybersecurity / Threat Detection
Deliverable
production ML models
Required skills
SIEM, SOAR, EDR, cloud security platforms, Python, PowerShell, detection-as-code, CI/CD pipelines, MITRE ATT&CK framework
Preferred skills
GIAC GCTI, GCFA certifications
Technologies
SIEM, SOAR, EDR, NDR, Python, PowerShell
Responsibilities
Develop, test, and maintain detection rules and logic; Review and enhance detection logic to improve accuracy and reduce noise; Automate detection rule deployment, QA, and version control; Conduct Root Cause Analysis on missed detections and high-severity incidents; Maintain a Continuous Security Improvement backlog; Collaborate with SOC, Incident Response, and Threat Hunting teams; Contribute to purple team exercises by validating detection logic against simulated attack paths.
Seniority
Individual Contributor