Detection Engineer
Core
Designing high-fidelity detection logic across Microsoft Sentinel, SentinelOne, and Splunk to reduce noise and enable AI-assisted triage for SOC analysts.
Role type
Mid-level Security Detection Engineer
Builds
Detection rules and logic for SIEM platforms
Domain
Cybersecurity / SOC Operations
Required skills
Detection engineering, SIEM rule authoring, query language fluency, MITRE ATT&CK mapping, false positive reduction, incident triage coordination
Preferred skills
Computer science qualification, SC-200, Blue Team Level 1/2, SANS Incident Responder, GIAC GCDA
Technologies
Microsoft Sentinel, SentinelOne, Splunk
Responsibilities
Design high fidelity detections for subtle or evasive behaviours, Tune the highest volume rules by finding the root cause of noise, Translate customer risk profiles into a prioritised detection strategy, Audit customer logging against intended coverage and map to MITRE ATT&CK, Turn threat tradecraft and intelligence reporting into concrete detection logic, Perform SIEM based event analysis and incident triage
Seniority
Mid-level, hands-on IC