Detection Engineer
Tasks
- Build scripts for log parsing and data normalization
- Build tune and maintain detection logic
- Conduct threat hunting with adversary TTP modeling
- Design and maintain SOAR playbooks
- Develop enrichment and response workflows
- Document incident response evidence for audits
- Implement detection-as-code workflows
- Integrate AI assisted triage validation
- Integrate SOAR with SIEM EDR and threat intelligence
- Lead incident response and escalation for complex threats
- Map detection coverage to MITRE ATT&CK
- Optimize signal-to-noise ratio
- Perform incident triage during on call
- Report security metrics and detection performance
- Translate threat intelligence into detections
Perks/Benefits
Skills/Tech-stack
AWS GuardDuty | AWS Inspector | AWS Security | AWS Security Hub | AWS Security Lake | Access Management | Amazon Web Services | Anomaly Detection | Behavioral analytics | CI/CD | Detection engineering | Detection-as-code | EDR | Git | Identity and Access Management | Identity and access | Incident Response | KMS | MITRE ATT&CK | NDR | Python | REST APIs | SIEM | SOAR | Security Hub | Security Lake | Shell Scripting | Sigma | Terraform | Threat Intelligence | Threat hunting | Web Services | Yara | “as-code”
Education
Roles
Detection Engineer | Engineer | Security | Security Engineer
Related jobs
-
Incident Response Analyst III USD 94K-148KCause analysis | Code Automation | Detection engineering | Digital forensics | EDRSenior-level Full TimeWaltham, Massachusetts, United States R20h ago
-
Security Engineer USD 122K-162KAWS | Bash | CIS Benchmarks | CloudFormation | ComplianceContinuous learning | On-call rotation | Supportive team environmentMid-level Full TimeUSA (remote) R21h ago
-
Mid-level Full TimeUS- remote R21h ago
-
Cybersecurity Engineer USD 123K-166K800-53 | ACAS | ATO | AWS | Access Control401k retirement plan | Conference attendance | Dental insurance | Disability insurance | Flexible time offMid-level Full TimeUnited States - Remote R1d ago
-
Application Security Engineer Prin USD 111K-198KAPI Security | API vulnerabilities | AWS | Application Security | Atlassian SuiteCharity opportunities | Recognition programs | Remote work | Time away from work programs | Volunteer daysMid-level Full TimeUnited States R1d ago
-
Application Security Engineer Prin USD 111K-198KAPI Security | AWS | Access Management | Application Security | Application Security TestingCareer growth opportunities | Community impact | Equal opportunity employer | Recognition programs | Remote workMid-level Full TimeUnited States R1d ago
-
Senior Engineer, Security (AppSec) USD 145K-190KAWS | Access Management | Alert Tuning | Application Security | Auth0Employee development programs | Employee driven initiatives | Remote-friendly work environmentSenior-level Full TimeRemote (USA) R1d ago
-
Operational Technology (OT) Security Engineer USD 104K-154KACAS | Anomaly Detection | Asset monitoring | BACnet | Change Management401k match | Commuter benefits | Dental insurance | Disability insurance | Educational reimbursementSenior-level Full TimeUnited States - Remote R1d ago
-
Principal Engineer - Secure by Design; AppDev/SDLC/Crypto CTO/DCMS Security Solution Architect USD 305KAI Security | Access Management | Application Security | Cloud Security | Container Security401k plan | Commuter benefits | Disability benefits | Health benefits | Life insuranceSenior-level Full Time112265-NJ-MetroPark, Iselin, United States R1d ago
-
Software Engineer I - Frontend USD 86K-146KAWS | Automated testing | CI/CD | CSS | GitLabRemote workEntry-level Full TimeVirtual - Illinois, United States R1d ago
-
Lead DevSecOps Engineer, Cloud (Azure), Hybrid Schedule USD 153K-170KAKS | Ansible | AppDynamics | Azure DevOps | Azure KubernetesEmergency restoration assignment | Hybrid schedule | Mentorship | Travel as neededSenior-level Full TimeBerlin, CT, United States R1d ago
-
800-53 | ARM Templates | AWS | AWS CloudFormation | AgileEntry-level Full TimeNationwide Remote Office (US99), United States R1d ago
-
Security Engineer USD 98K-228KAWS | Application Security | Authentication | Authorization | Burp SuiteHybrid work | Remote workMid-level Full TimeRemote (US), United States R1d ago
-
Senior Systems Engineer USD 90K-125KAmazon Web Services | Cloud platform | DNS | Disaster Recovery | FirewallDental/Vision plan | Health insurance | Professional development stipend | Remote workSenior-level Full TimeNew York, New York, United States R1d ago
-
Application Security Engineer USD 107K-195KAccess Management | Application Security | CI/CD | Code review | Compliance EvidenceSenior-level Full Time6314 Remote/Teleworker US, United States R1d ago
-
Sr. Backend Engineer - Managed Services (Hybrid) USD 140K-215KAmazon Kinesis | C++ | Cloud Native | Cloud Observability | Cloud-native technologiesEmployee networks | Hybrid work | On-call coverage | Paid adoption leave | Paid parental leaveSenior-level Full TimeSunnyvale, United States R1d ago
-
AWS | Algorithms | Azure | Cloud Monitoring | Cloud NativeEmployee networks | Great Place to Work certification | Hybrid work | Paid adoption leave | Paid parental leaveSenior-level Full TimeSunnyvale, United States R1d ago
-
Anti-Malware | Application Firewall | Data Loss Prevention | Data loss | Event analysisComprehensive healthcare | Flexible time off | Flexible work model | Hybrid work model | Leave benefitsMid-level Full TimeDE2-Wilmington - 400 Bellevue Parkway, United … R1d ago
-
AWS | Bash | CI/CD | Cloud platform | DockerAdoption leave | Employee networks | Hybrid work | Office culture | Paid parental leaveSenior-level Full TimeSunnyvale, United States R1d ago
-
AWS | Agent Frameworks | Agentic AI | Azure | Cloud infrastructureEmployee volunteer opportunities | Paid adoption leave | Paid parental leave | Paid time off | Professional development opportunitiesSenior-level Full TimeSunnyvale, United States R1d ago
-
Staff Security Engineer USD 160K-200KAI Security | AWS | Application Security | Authentication | Authorization401k match | Company-sponsored events | Flexible work policy | Global workforce | Paid parkingSenior-level Full TimeAustin, Texas R2d ago
-
Senior Application Security Engineer USD 148K-171KAPI Security | AWS GuardDuty | AWS IAM | AWS KMS | AWS SecurityCompany days off | Professional development budget | Remote work | Self-improvement budget | Travel reimbursementSenior-level Full TimeRemote - USA R2d ago
-
.NET | API Management | AWS EC2 | AWS ECS | AWS LambdaBackground check required | Hybrid work | Relocation requiredSenior-level ContractDauphin, United States R3d ago
-
Sr .NET Lead Engineer & IAM Specialization - hybrid USD 119K-164K.NET | ASP.NET | Auth0 | C# | ClaimsAgile team leadership | Hybrid workSenior-level ContractDallas, United States R3d ago
-
Senior Security Engineer, Enterprise SaaS USD 153K-186KAccess Management | Alert triage | Automation | Cloud Security | Configuration Management401k match | Counseling services | Dental insurance | Dependent Care Flexible Spending Account | Fertility benefitsSenior-level Full TimeNew York, NY or Remote R3d ago