Senior Detection Engineer (AI-ML Focus)
Core
Building, tuning, and scaling detection capabilities across enterprise SIEM platforms using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development and validation.
Role type
Senior Detection Engineer (AI-ML Focus)
Builds
Detection rules, detection-as-code pipelines, and AI-augmented triage systems for enterprise security operations.
Domain
Cybersecurity / Threat Detection / AI Engineering
Deliverable
production ML models | product features
Required skills
SIEM detection rule design and tuning, MITRE ATT&CK framework application, Python for automation and scripting, Git-based workflows (branching, PRs, CI/CD), security log source familiarity (EDR, identity, cloud, network, proxy), analytical skills for distinguishing threats from noise.
Preferred skills
CISSP/CCSP/OSCP/GCDA certifications, detection-as-code practices (Sigma, YAML), AI/LLM security implications knowledge, MCP server experience, SOAR platform integration, Kubernetes/cloud-native architecture understanding.
Technologies
SIEM platforms, Data Lake, Git, CI/CD pipelines, Python, MCP (Model Context Protocol), SOAR platforms, Kubernetes.
Responsibilities
Design, build, test, and tune detection rules mapped to MITRE ATT&CK; Write detection logic across SIEM and data lake platforms; Manage detection content as code via Git-based workflows; Investigate and suppress false positives using lookup-based architectures; Leverage AI agents and LLM-assisted workflows to accelerate rule development and validation; Collaborate with SOC analysts and data engineers on alert quality and telemetry availability.
Seniority
Senior, hands-on IC