CareerPlanGet AI match score →

Senior Detection & Response Engineer

2 Locations💼 Full-time🗓 2026-06-30 → 2026-07-31

Core

Design, build, and tune detection rules for SIEM and security tooling; lead end-to-end incident response investigations including forensic analysis and containment; develop automation and playbooks to accelerate security operations.

Role type

Senior Detection & Response Engineer (Security Operations)

Builds

Detection rules, automation scripts, incident response playbooks, and forensic analysis artifacts

Domain

Cybersecurity, Identity Security, Cloud Security, Endpoint Security

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

detection engineering, incident response, digital forensics, scripting (Python/PowerShell/KQL), API integration, EDR platform usage, SIEM rule development, hybrid identity management, attacker tradecraft analysis, root cause analysis

Preferred skills

AI tooling for security workflows, Microsoft Sentinel (KQL/Logic Apps), Microsoft Entra ID/Purview/Defender Suite, CrowdStrike Falcon, identity security tooling (Saviynt/IGA), large enterprise environment experience

Technologies

Python, PowerShell, KQL, Microsoft Sentinel, Microsoft Entra ID, CrowdStrike Falcon, Saviynt, AD Connect

Responsibilities

Design and tune detection rules across SIEM and security tooling; build scripts and automation for detection engineering and response workflows; lead incident response investigations from triage to closure; perform host and cloud forensic analysis; investigate EDR detections and process trees; analyze Microsoft 365 and Entra ID log sources; develop and maintain automated response playbooks; identify and tune false positive patterns

Seniority

Senior, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Workday ↗