Security Detection Engineer
Core
Design, build, and scale high-fidelity, scalable detection capabilities to protect millions of members' biometric and health data across cloud, identity, endpoint, and application environments.
Role type
Security Detection Engineer (IC)
Builds
High-signal detections, detection logic, behavioral protections, and automated triage workflows
Domain
Information Security / Cybersecurity / Cloud Security
Deliverable
production ML models | product features
Required skills
Detection engineering, threat detection, security operations, rule-based detection methodologies (YARA, SIGMA, Suricata), attacker technique analysis, cloud and SaaS telemetry analysis, scripting (Python, Go, PowerShell), incident response, systems thinking
Preferred skills
Consumer-facing platform detection, authentication and API abuse detection at scale, data analysis, machine learning techniques for security
Technologies
YARA, SIGMA, Suricata, Python, Go, PowerShell
Responsibilities
Design and build detections across cloud, identity, endpoint, network, and application layers; Develop detection logic aligned to MITRE ATT&CK; Translate threat intelligence into actionable detections; Build behavioral detections for account takeover, credential abuse, and data exfiltration; Tune alerts and reduce false positives; Define and track detection KPIs; Support incident investigations and on-call rotation; Partner with Engineering and Product teams; Map detections to threat models; Apply advanced analytics and ML to improve detection fidelity
Seniority
Mid-Senior, hands-on IC