Detection Engineer
Core
Building reliable data pipelines and detection logic for a Security Operations Center (SOC) to feed a SIEM platform, enabling AI-assisted threat triage and automation.
Role type
Software Engineer (Security Operations / Detection Engineering)
Builds
Log ingestion pipelines, detection-as-code workflows, and agentic SOC automation scripts for threat detection.
Domain
Cybersecurity / Security Operations Center (SOC) / SIEM
Deliverable
production ML models | infrastructure
Required skills
Python, API integration, unit testing, Git, problem-solving, cloud primitives (GCP/Azure/AWS), Docker
Preferred skills
SIEM exposure (Splunk, Sentinel), Infrastructure as Code (Terraform), IAM principles, scheduled jobs
Technologies
Python, Poetry, Git, CI/CD, Docker, GCP/Azure/AWS, Terraform, Splunk, Google SecOps, Microsoft Sentinel
Responsibilities
Build and maintain log ingestion pipelines; Normalize and forward events; Build tests and fix bugs; Operate pipelines reliably; Support detection engineering with guidance; Help manage and improve detection-as-code pipeline; Participate in code review; Build with agentic coding tools; Contribute to agentic workflows; Validate changes on historical data; Assist in building and maintaining SOAR automations.
Seniority
Mid-level, hands-on IC