Security Detection Engineer III
Core
Develop, test, deploy, and continuously improve detection capabilities for Security Operations by transforming threat intelligence and telemetry into actionable detections.
Role type
Senior IC security detection engineer
Builds
Scalable, threat-driven detection capabilities and automation workflows
Domain
Cybersecurity, Security Operations, Threat Intelligence
Deliverable
production ML models | product features
Required skills
Detection-as-Code, SIEM/EDR/log analytics platform experience, scripting (Python/PowerShell/SQL/KQL/SPL), MITRE ATT&CK framework, adversary emulation, atomic testing, purple-team exercises
Preferred skills
Detection coverage analysis, cloud/endpoint/network/identity/SaaS log onboarding, AI/LLM threat models (prompt injection, tool abuse, agent identity misuse, data exfiltration), AI acceleration of detection workflows
Technologies
Python, PowerShell, SQL, KQL, SPL, Git, CI/CD pipelines, CrowdStrike, Splunk, Microsoft Sentinel, Chronicle, Elastic
Responsibilities
Develop and maintain custom detections using version control, peer review, testing, and CI/CD; Analyze and improve detection coverage by mapping telemetry to adversary behaviors; Partner with Incident Response and Threat Intelligence teams to translate threats into actionable content; Validate and tune detections through adversary emulation and production feedback; Automate detection engineering workflows and alert enrichment; Support onboarding of new log sources and security telemetry; Create and maintain detection documentation and runbooks; Help define detection strategy for AI and agentic systems
Seniority
Senior, hands-on IC