Overview
Senior Expert Threat Detection & Response Engineer (individual contributor) who defines and builds detection/response technical capabilities, including AI/ML pipelines and detection-as-code workflows.
What you'll do
- Define, design, and build AI/ML pipelines for investigation, triage, enrichment, and detection generation.
- Own technical delivery of AI-assisted investigation and triage end-to-end from data foundations to safe production deployment.
- Design and own a detection-as-code pipeline with repository, schema, peer review, automated testing, and staged CI/CD deployment across SIEM, XDR, and endpoint surfaces.
- Design standards and reusable patterns for detection content quality and build guardrails to keep quality consistent across regions.
- Build automation and SOAR-style workflows to reduce response time (e.g., phishing clustering, DLP routing, enrichment, auto-closure of verified-benign reports).
- Establish MITRE ATT&CK coverage baseline and use it to identify gaps and redundancies for prioritizing engineering effort.
What you'll need
- Ability to design and build AI/ML pipelines that select/apply models to security data and deploy them with evaluation and guardrails.
- Detection and response as software: version, test, and ship detections like code; build tooling/APIs/pipelines to enable others.
- Deep hands-on detection engineering experience across SIEM and EDR/XDR platforms.
- Fluency in KQL/SQL/Sigma (or equivalent) and strong scripting/development skills (e.g., Python, Go).
- Threat-informed approach mapping detections to adversary behavior (ATT&CK) and thinking in coverage/exploitability/containment.
- Experience leading technical projects to completion and resolving hard engineering problems.
Details
- Work mode: Remote (US).
- Compensation: $151,700–222,400 annually; based on experience and qualifications.
Read the full description and apply on the company’s own careers page.