Threat Detection Engineer
Core
Designs, implements, and supports cyber security technology solutions, specifically focusing on threat detection, alert tuning, and incident response within cloud applications and infrastructure.
Role type
Senior Threat Detection Engineer (SOC)
Builds
Production detection rules, dashboards, and security monitoring capabilities for cloud and on-prem environments
Domain
Cybersecurity / Threat Intelligence / Cloud Security
Deliverable
production ML models | dashboards & analysis | client delivery
Required skills
Splunk Enterprise Security (ES), SPL query development, MITRE ATT&CK mapping, Python, PowerShell, regex, Git-based Detection-as-Code, risk-based alerting (RBA), log normalization (CIM), Windows Security Events, Sysmon, cloud logging (AWS/Azure)
Preferred skills
CISSP, CompTIA Security+, CCNA, MCSA, threat hunting, red/purple team collaboration
Technologies
Splunk, MITRE ATT&CK, Python, PowerShell, Git, AWS, Azure, Microsoft Defender, CrowdStrike, Palo Alto, Okta, Sysmon
Responsibilities
Design and implement cyber security technology solutions; conduct research and proof-of-concept for new security tools; tune alerts and reduce false positives; map detections to adversary behaviors; support security incident response activities; collaborate with threat hunters and SOC analysts; document detections and security recommendations.
Seniority
Senior, hands-on IC