Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments. You will improve the detection platform, develop automation for triage and investigations, translate threat intelligence into detections, participate in incident response and postmortems, track detection metrics, and join an on-call rotation.
Requirements
- 3+ years of experience in detection engineering, security operations, incident response, threat hunting, or a related security or software engineering role
- Experience writing or tuning production detections with attention to signal quality
- Working knowledge of Sigma, KQL, SPL, YARA-L, EQL, Panther, SQL, or Python
- Understanding of attacker operations and MITRE ATT&CK
- Hands-on experience with AWS, GCP, or Azure, including identity and access logs
- Experience using SIEM, EDR, or SOAR tools
- Ability to write runbooks, design documents, and incident notes and own well-scoped projects end to end
Responsibilities
- Build and tune high-signal detections across cloud, identity, endpoint, and SaaS environments
- Contribute to the detection platform, including rule lifecycle management, tuning, measurement, and rollout safety
- Build tooling and automation for triage, enrichment, investigation, and detection authoring
- Turn threat intelligence and adversary TTPs into detections, telemetry requirements, and response improvements
- Participate in investigations, incident response, and postmortems
- Define and track metrics including coverage, MTTD, and alert quality
- Join a shared on-call rotation for incident response
Benefits