Posted on: 06/10/2026
Role Overview :
We are looking for a Senior Detection Engineer - Cloud & Endpoint to join our Integrations Team. You will be responsible for providing technical direction to deliver high-value, performant, generalized detections across endpoint, network, cloud, identity, and email telemetry sources.
What you will do :
- Act as a technical leader and mentor to detection engineers across the XDR program.
- Apply expertise across multiple telemetry domains to design detections that generalize across diverse customer environments.
- Develop detections, correlation rules, and analytics based on telemetry ingested from third-party integrations.
- Research emerging threats, attack techniques, and adversary tactics.
- Map detections to the MITRE ATT&CK framework and maintain alignment with evolving threat landscapes.
- Validate detections against attack simulations, threat scenarios, and real-world telemetry.
What we are looking for :
- 6+ years of experience in Detection Engineering, Threat Hunting, Security Research, SOC Engineering, or Security Analytics.
- Expert-level Python expertise, with the ability to build detection tooling, automation, and frameworks.
- Deep understanding of diverse telemetry sources : Endpoint (Windows Security, Sysmon, Linux auditd, macOS, EDR), Network (NetFlow, DNS, HTTP/TLS), Cloud (AWS CloudTrail, Azure Activity, GCP Audit, Kubernetes), Identity (Okta, Azure AD/Entra ID), and Email.
- Hands-on experience with detection technologies such as KQL, SPL, Sigma, or SQL.
- Strong understanding of adversary TTPs and the MITRE ATT&CK framework.
- Experience providing technical guidance and mentoring to other detection engineers.
Nice to have :
- Experience with SIEM, XDR, MDR, CNAPP, or Identity Threat Detection platforms.
- Familiarity with security data normalization frameworks such as OCSF.
- Experience with attack simulation and detection validation.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1676785