Threat Detection Analyst (Expert)
Core
Develops, tunes, validates, and maintains high-fidelity threat detections across enterprise security platforms to identify malicious activity and reduce detection gaps.
Role type
Senior Threat Detection Analyst (Detection Engineering)
Builds
Detection content (rules, analytics, correlation logic) for SIEM, XDR, EDR, and cloud security platforms
Domain
Cybersecurity / Threat Detection / Security Operations
Deliverable
production ML models | product features
Required skills
Threat detection engineering, MITRE ATT&CK framework, adversary emulation, detection validation, security telemetry analysis, detection gap assessment, false positive reduction, detection documentation, log source requirements, security metrics reporting
Preferred skills
Palo Alto Cortex XSIAM, Microsoft Sentinel, Splunk, Microsoft Defender XDR, detection-as-code, KQL/SPL/XQL/SQL, Python/PowerShell/Bash scripting, network protocols (HTTP/S, DNS, SMTP, SSH, LDAP, Kerberos), cybersecurity frameworks (NIST CSF, Cyber Kill Chain), threat hunting, cloud security telemetry, Windows/Linux/macOS/Active Directory/Azure AD
Technologies
SIEM, XDR, EDR, Palo Alto Cortex XSIAM, Microsoft Sentinel, Splunk, Microsoft Defender XDR, Python, PowerShell, Bash, KQL, SPL, XQL, SQL
Responsibilities
Design, develop, test, deploy, and maintain threat detections; conduct detection validation via threat simulations and adversary emulation; analyze threat intelligence and attack techniques; tune detection logic to optimize fidelity; perform detection gap assessments; create and maintain detection documentation and coverage mappings; partner with Incident Response and Threat Intelligence teams; measure and report on detection health and performance metrics
Seniority
Senior, hands-on IC with mentorship responsibilities