Principal Threat Detection Operations Engineer
Core
Set technical strategy and lead the design, development, and operationalization of scalable detection capabilities to identify sophisticated cyber threats across enterprise environments.
Role type
Principal Threat Detection Operations Engineer
Builds
Scalable detection capabilities, services, integrations, automations, and analyst-facing tooling
Domain
Cybersecurity / Threat Detection / Cloud Security
Deliverable
production ML models | product features
Required skills
Python programming, detection engineering, SIEM platforms, detection-as-code, CI/CD, behavioral analytics, correlation logic, secure systems design, adversary behavior analysis, cloud technologies, SQL/NoSQL, Git, containerization
Preferred skills
Threat hunting, SOAR, EDR, threat intelligence, identity security, malware analysis, REST APIs, Kubernetes
Technologies
Python, SIEM, EDR, SOAR, Git, Kubernetes, SQL, NoSQL, Cloud platforms
Responsibilities
Define technical vision and roadmap for detection engineering; Architect and develop scalable detection rules and pipelines; Establish engineering standards for detection content and operations; Partner with incident responders to translate threat intelligence into durable capabilities; Define metrics to measure detection coverage and operational performance; Mentor engineers and analysts; Evaluate detection technologies via proofs of concept and vendor assessments.
Seniority
Principal, hands-on IC with leadership