Threat Detection Engineer
Core
Design, develop, and optimize threat detection capabilities across security platforms, focusing on building advanced detection logic, improving visibility, and identifying emerging threats.
Role type
Threat Detection Engineer
Builds
Detection logic, rules, alerting, and playbooks for SIEM and SOAR solutions
Domain
Cybersecurity, Threat Detection, Security Operations
Deliverable
production ML models | product features | dashboards & analysis
Required skills
SIEM, EDR, XDR, SOAR, NDR, threat hunting, incident handling, log analysis, IOC identification, network protocol knowledge, SIEM rule/query writing, threat intelligence gathering
Preferred skills
consulting or advisory experience, content tuning, advanced malicious activity identification, integration of SIEM into customer environments
Technologies
SIEM, EDR, XDR, SOAR, NDR, IPS, IDS, HIPS, firewalls, Office 365, DNS, Windows Event Logs, syslog
Responsibilities
Conduct threat detection, incident handling, and hunting activities; proactively hunt for misconfigurations in SIEM solutions; develop use cases and create threat detection logic, rules, and alerting; contribute to the management of playbooks in SOAR solutions; identify gaps in log collection and visibility; assist customers with SIEM integration requests
Seniority
Mid-level, hands-on IC