Overview
Staff Information Security Engineer for Detection Engineering, defining and driving detection strategy across endpoint, identity, cloud, and SaaS environments.
What you'll do
- Define a detection strategy and roadmap across priority threat scenarios.
- Partner with IR/Threat Intel/Cloud/IAM to turn hypotheses and TTPs into production detections and lead purple-team validation.
- Design detections-as-code with version control, CI/CD, unit/integration tests, and staged rollouts.
- Lead adversary emulation exercises and develop synthetic signal and test harnesses.
- Perform proactive threat hunting and convert findings into detections.
- Build IR automation (SOAR/Logic Apps) for triage, enrichment, containment, and case workflow.
- Operationalize threat intelligence by ingesting/normalizing IOCs/TTPs and enriching detections with TI context.
What you'll need
- 5+ years in security engineering, detection engineering, or incident response.
- 2+ years technical leadership experience.
- Expertise with log analytics and detection content for SIEM/XDR/EDR and cloud provider telemetry (AWS/Azure/GCP).
- Experience building detections and automation with scripting languages (e.g., Python) and query languages (e.g., KQL/SQL).
- Experience building detections-as-code (tests, CI/CD, canary deploys, rollback) at large scale.
- Experience with attacker TTPs and frameworks (ATT&CK) and detection efficacy metrics.
- Experience designing schemas/data models and telemetry pipelines.
Details
- Location: Mountain View, CA, United States.
- Work mode: role may be remote or hybrid; can be remote anywhere in the United States or hybrid in LinkedIn’s Mountain View office.
- Includes on-call for critical detection pipelines and high-severity investigations.
Read the full description and apply on the company’s own careers page.