Senior Detection Engineer (AI-Augumented)
Core
Building, tuning, and scaling detection capabilities across enterprise SIEM platforms using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development and validation.
Role type
Senior Detection Engineer (AI-Augmented)
Builds
Detection rules, alert logic, and agentic pipelines for triaging rule libraries against live telemetry.
Domain
Cybersecurity / Threat Detection / SIEM
Deliverable
production ML models | product features
Required skills
Detection rule design and tuning, SIEM analytics, MITRE ATT&CK framework, Python scripting, Git-based workflows (CI/CD), Security log source analysis (EDR, identity, cloud, network, proxy), Threat intelligence integration, False positive suppression, Anomaly detection techniques, Behavioral analytics, Pattern identification in security datasets.
Preferred skills
Multiple query languages, Detection-as-code (YAML/Sigma), MCP servers, GitHub Copilot, SOAR platforms, Kubernetes, Cloud-native architectures, OT/ICS environments.
Technologies
SIEM platforms, Data lake platforms, Git, CI/CD pipelines, Python, MITRE ATT&CK, MCP (Model Context Protocol), LLMs, SOAR, Kubernetes.
Responsibilities
Design, build, test, and tune detection rules mapped to MITRE ATT&CK; Write detection logic across SIEM and data lake platforms; Manage detection content as code via git-based workflows; Investigate and suppress false positives using lookup-based architectures; Collaborate with Threat Hunting and Threat Intelligence teams; Leverage AI agents and LLM-assisted workflows to accelerate rule development and validation; Operate agentic pipelines for triaging rule libraries; Apply AI/ML techniques for anomaly detection and behavioral analytics; Monitor emerging threats and develop detections for new TTPs and CVEs.
Seniority
Senior, hands-on IC