CareerPlanSign in

Security Detection Engineer III

Warsaw, PL💼 Full-time🗓 2026-08-25 → 2026-09-25

Core

Develop, test, deploy, and continuously improve detection capabilities for Security Operations by transforming threat intelligence and telemetry into actionable detections.

Role type

Senior IC security detection engineer

Builds

Scalable, threat-driven detection capabilities and automation workflows

Domain

Cybersecurity, Security Operations, Threat Intelligence

Deliverable

production ML models | product features

Required skills

Detection-as-Code, SIEM/EDR/log analytics platform experience, scripting (Python/PowerShell/SQL/KQL/SPL), MITRE ATT&CK framework, adversary emulation, atomic testing, purple-team exercises

Preferred skills

Detection coverage analysis, cloud/endpoint/network/identity/SaaS log onboarding, AI/LLM threat models (prompt injection, tool abuse, agent identity misuse, data exfiltration), AI acceleration of detection workflows

Technologies

Python, PowerShell, SQL, KQL, SPL, Git, CI/CD pipelines, CrowdStrike, Splunk, Microsoft Sentinel, Chronicle, Elastic

Responsibilities

Develop and maintain custom detections using version control, peer review, testing, and CI/CD; Analyze and improve detection coverage by mapping telemetry to adversary behaviors; Partner with Incident Response and Threat Intelligence teams to translate threats into actionable content; Validate and tune detections through adversary emulation and production feedback; Automate detection engineering workflows and alert enrichment; Support onboarding of new log sources and security telemetry; Create and maintain detection documentation and runbooks; Help define detection strategy for AI and agentic systems

Seniority

Senior, hands-on IC

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.