Posted on: 29/08/2026
Job Description :
The team :
This role reports into the Security Operations function, owns the strategic direction for the detection engineering portfolio, and partners closely with the Security Data Services and Data Platforms teams and the Security Operations Center.
The role :
You'll own the detection portfolio as a system, building and managing coverage across the enterprise: what we detect, why, what data it takes, and what it costs the SOC in attention.
Analyst focus is finite, and every alert we ship spends some of it a large part of this job is deciding which assets and which behaviors are worth that spend, and building the framework that makes those calls consistent. You'll work upstream with Data Services to shape telemetry before a detection is ever written, and downstream with the SOC to make sure what ships is worth working. This is a senior-level role and we expect you to set direction, not take it.
What you'll do :
- Roll up your sleeves to build core parts of the detection strategy and coverage against the threats that actually reach our environment. We are informed by models such as MITRE ATT&CK to identify gaps, but we expect more than just a list of coverage techniques an understanding of adversary tradecraft, evasion, and trade-offs are all part of what makes this portfolio successful.
- Build the framework that ties asset criticality and business impact to detection thresholds, severity, and routing and the measures that show whether a detection is earning its place.
- Specify telemetry requirements upstream : what we collect, how it maps to OCSF, what enrichment it needs, what latency and retention each source requires, and when a source costs more than it reveals.
- Design detections across the full estate real-time analytics where speed matters, scheduled analytics over long-retention data where history and breadth matter, including retroactive analysis against data we already hold.
- Establish detection-as-code practice : version control, testing, CI/CD, and monitoring that catches silent failures and degraded sources. Document detections in an ADS-style format that states blind spots, expected false positives, and how the detection was validated.
- Run hypothesis-driven analysis to find what should become a detection, then make it durable and automated.
- Mentor engineers, write the documents that outlive the project, and carry detection requirements into architecture and platform reviews.
What you bring :
- Depth in adversary tradecraft : 8+ years in security or detection engineering, with real fluency in multiple coverage domains to include application-level, endpoint, identity, cloud control plane, SaaS, and network and the ability to reason from a technique to the evidence it leaves behind.
- Data engineering fundamentals : Strong SQL, shell scripting, a general-purpose language such as Python, and experience working with event data at scale.
- Schema reasoning : You've built against a normalized event model, whether that's OCSF or otherwise, and know what mapping costs and where it breaks.
- Systems judgment : Streaming versus batch detection, and the cost, latency, and retention trade-offs each carries.
- Detections as software : Source control, testing, peer review, automated deployment.
- Upstream influence : You've shaped collection, schema, or pipeline decisions alongside a data or platform team.
- Writing : At this level, direction gets set in documents.
- Nice to have : hands-on experience with Palantir platforms and ADS methodology; time spent on a SOC queue receiving detections you didn't write; hands-on experience evading detections with adversarial tradecraft and threat/security research; experience building a detection quality metrics program; contributions to open detection content or tooling.
Did you find something suspicious?
Posted by
Veeranna
Talent Acquisition Executive at EKFRAZO TECHNOLOGIES PRIVATE LIMITED
Last Active: 29 Aug 2026
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1667044