Staff Detection Engineer
San Jose, United States
Full Time Senior-level / Expert USD 160K - 297K
Adobe
Adobe is changing the world through digital experiences. We help our customers create, deliver and optimize content and applications.Our Company
Changing the world through digital experiences is what Adobe’s all about. We give everyone—from emerging artists to global brands—everything they need to design and deliver exceptional digital experiences! We’re passionate about empowering people to create beautiful and powerful images, videos, and apps, and transform how companies interact with customers across every screen.
We’re on a mission to hire the very best and are committed to creating exceptional employee experiences where everyone is respected and has access to equal opportunity. We realize that new ideas can come from everywhere in the organization, and we know the next big idea could be yours!
The Staff Detection Engineer is a senior, highly technical role responsible for advancing Adobe’s threat detection and response capabilities. This role leads the full lifecycle of our threat detection engineering - from designing detection instrumentation including logic and telemetry systems to automating responses across cloud, on-premise, and endpoint environments.
As a technical leader, you will craft our detection strategy based on the evolving threat landscape, mentor engineers, and collaborate with multi-functional teams to proactively mitigate threats.
At Adobe, we believe in collaboration and collective ownership to solve complex security challenges. We'll rely on your skills and experience to drive innovation from day one. We are not a team that accepts the status quo! We are focused on solving critical, complex issues.
Responsibilities
- Define and drive the strategic vision, technical roadmap, and maturity targets for detection and automated response capabilities.
- Question existing workflows and suggest improvements that would enable us to better scale, improve fidelity, streamline response efforts, etc.
- Architect and maintain scalable, automated security discovery and containment systems.
- Guide the adoption and integration of new detection technologies, frameworks, and standard processes.
- Create, test, deploy, and enhance behavioral, rule-based, and machine learning detections from diverse security signals and telemetry.
- Improve accuracy, efficacy, and efficiency of detections by reviewing alert fidelity, signal-to-noise ratios, recall/precision, and other operational key performance indicators.
- Operate and maintain CI/CD pipelines and custom tooling for reliable content delivery.
- Establish and author repeatable and scalable processes around detection and automation engineering.
- Find opportunities and implement automation for detection, response, and operational workflows.
- Collaborate with teams across Adobe such as incident response, threat intelligence, security engineering, hunt team, red team, risk management, and product teams to validate coverage across various data sources and security telemetry, and to uncover and address blind spots.
- Communicate complex detection engineering concepts to both technical and non-technical partners, including leaders.
- Drive high impact cross-team projects and initiatives.
- Provide technical leadership, coaching, and mentorship to other engineers and analysts, fostering a culture of continuous learning and improvement.
Essential Strengths and Technical Skills
- In-depth knowledge of the cyber threat landscape, attacker tactics and techniques, and frameworks such as MITRE ATT&CK.
- Extensive experience with detection rule languages (e.g., SPL, KQL) and advanced query development.
- Deep functional knowledge of writing detections based on network traffic (e.g., Snort, Suricata, Yara, etc.) and familiarity with network and packet analysis.
- Solid experience with incident response, security operations, threat hunting, and offensive security.
- Deep expertise in SIEM/SOAR platforms (e.g., Splunk, Sentinel, Elastic, QRadar, etc.).
- Experience with DevOps style CI/CD.
- Strong programming / scripting skills (e.g., Python, PowerShell, Bash, SQL, etc.)
- Firm understanding of diverse operating systems, networking concepts, security tools such as EDR, WAF, or DLP, and the services, logging, telemetry, and monitoring capabilities for the major cloud platforms.
- Strong ability to analyze large-scale security data, signals, and telemetry to identify patterns, derive meaningful insights, and translate into compelling visualizations.
- Ability to integrate and operationalize threat intelligence and perform in-depth threat modeling.
- Expertise in identifying, analyzing, and responding to sophisticated threats.
- Strong technical leadership and mentoring skills
Preferred Qualifications
- Experience building detection programs at scale in large, complex, cloud-inclusive environments including orchestration and automation of workflows.
- History of creating anomaly detection pipelines for security purposes.
- Advanced knowledge of adversary emulation, offensive security, threat modeling, and digital forensics.
- Experience implementing and managing detection content as code using Git, CI/CD (Detection-as-Code).
- Track record of speaking at security conferences or publishing research or white papers.
- Extensive experience driving technical direction and mentoring.
What You Need to Succeed
- 10+ years in cybersecurity, with a significant portion focused on detection engineering, threat hunting, incident response, or offensive security.
- Ability to think strategically with hands-on technical execution.
- Ability to translate threat intelligence into detection engineering roadmaps.
- Excellent written and verbal communication skills with the ability to communicate technical risk and impact in a business context.
- Collaborative attitude for effective collaboration across teams.
- Dedication to ongoing professional development and team growth.
- Dedication to operational excellence by using a data-based approach to evaluate efficiency and foster improvements.
- Combination of technical mastery, an adversarial mentality, strategic vision, and proven leadership qualities.
At Adobe, for sales roles starting salaries are expressed as total target compensation (TTC = base + commission), and short-term incentives are in the form of sales commission plans. Non-sales roles starting salaries are expressed as base salary and short-term incentives are in the form of the Annual Incentive Plan (AIP).
In addition, certain roles may be eligible for long-term incentives in the form of a new hire equity award.
State-Specific Notices:
California:
Fair Chance Ordinances
Adobe will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and “fair chance” ordinances.
Colorado:
Application Window Notice
If this role is open to hiring in Colorado (as listed on the job posting), the application window will remain open until at least the date and time stated above in Pacific Time, in compliance with Colorado pay transparency regulations. If this role does not have Colorado listed as a hiring location, no specific application window applies, and the posting may close at any time based on hiring needs.
Massachusetts:
Massachusetts Legal Notice
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Adobe is proud to be an Equal Employment Opportunity employer. We do not discriminate based on gender, race or color, ethnicity or national origin, age, disability, religion, sexual orientation, gender identity or expression, veteran status, or any other applicable characteristics protected by law. Learn more.
Adobe aims to make Adobe.com accessible to any and all users. If you have a disability or special need that requires accommodation to navigate our website or complete the application process, email accommodations@adobe.com or call (408) 536-3015.
Tags: Automation Bash CI/CD Cloud Compliance DevOps EDR Forensics Incident response Machine Learning MITRE ATT&CK Monitoring Offensive security PowerShell Python QRadar Red team Risk management Scripting Sentinel SIEM Snort SOAR Splunk SQL Strategy Threat detection Threat intelligence
Perks/benefits: Career development Conferences Equity / stock options Startup environment Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.