Security Engineer - Detection Engineering and Threat Modeling
Core
Design and enhance detection capabilities, onboard secure data sources, and drive automation to improve Security Operations Center (SOC) effectiveness.
Role type
Security Engineer (Detection Engineering and Threat Modeling)
Builds
Detection rules, ingestion pipelines, and automation solutions for the SOC
Domain
Cybersecurity, Threat Detection, SIEM Operations
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SIEM detection rule tuning, log source onboarding, threat modeling, Python, KQL, SQL, log ingestion pipelines, MITRE ATT&CK frameworks
Preferred skills
Microsoft Sentinel, Defender Suite, Azure, AWS, Docker, Linux, detection-as-code, CI/CD security processes
Responsibilities
Design and tune SIEM detection rules to reduce false positives; Build ingestion pipelines to onboard and normalize new log sources; Perform threat modeling to identify security gaps; Develop automation solutions to improve SOC workflows; Collaborate with teams to enhance detection coverage against evolving threats; Apply threat intelligence frameworks to strengthen monitoring capabilities
Seniority
Mid-level, hands-on IC