Detection Development Intern, Fall 2026
Core
Building and tuning threat detection rules for SaaS platforms and cloud technologies within a Security Operations Center (SOC) to identify suspicious activity and improve visibility.
Role type
Detection Engineering Intern
Builds
Threat detection rules for SaaS platforms (e.g., 1Password, AWS) and log sources (e.g., Cortex XDR) using XSIAM.
Domain
Enterprise Security / Cloud Security / SaaS
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Analytical thinking, familiarity with SIEM concepts, knowledge of security tooling, ability to research threat actor abuse vectors, log analysis, understanding of user activity and system behavior.
Preferred skills
Experience with Capture The Flag (CTF) competitions, personal security projects, curiosity about security systems.
Technologies
XSIAM, 1Password, AWS, Cortex XDR
Responsibilities
Build and tune detection rules in XSIAM for various technologies and log sources; research potential abuse vectors for services and tools; analyze logs and security telemetry to understand user activity and system behavior; participate in daily stand-up meetings and collaborate with team members; contribute to detection coverage discussions.
Seniority
Intern