AP

Senior Threat Detection Specialist

Hiring from
United Arab Emirates
Work type
Remote
Posted
Is this job info correct?

507,569 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description
We're Hiring: Senior Threat Detection Specialist

Location: United Arab Emirates (Remote)

Employment Type: Full-Time

Experience Level: Senior

Work Arrangement: Fully Remote

About Us

We are a globally focused organization committed to protecting digital infrastructure, applications, data, and business operations from evolving cyber threats. Our security teams work across Security Operations, Engineering, Infrastructure, Cloud, Identity, Risk, Compliance, Data, and external security partners to strengthen threat visibility and organizational resilience.

We use modern detection engineering, security analytics, threat intelligence, automation, and continuous monitoring to identify malicious activity early, reduce response times, and improve the organization's overall security posture.

The Role

We are seeking an experienced Senior Threat Detection Specialist to lead threat detection engineering, security monitoring, detection analytics, threat hunting, and continuous improvement of security detection capabilities.

The ideal candidate will combine strong knowledge of cyber threats with expertise in SIEM, EDR/XDR, network security, cloud security, identity security, log analysis, detection engineering, threat intelligence, and security automation. The role will develop high-quality detections, investigate emerging attack techniques, reduce false positives, and work closely with incident-response and security-engineering teams to improve detection coverage.

Key Responsibilities
  • Develop and implement threat-detection strategies aligned with organizational security objectives.
  • Design, develop, test, deploy, and maintain security detection rules and analytics.
  • Build detection capabilities across endpoints, networks, cloud environments, applications, identities, and security infrastructure.
  • Develop detections for malware, credential theft, lateral movement, privilege escalation, persistence, command execution, data exfiltration, and other malicious activity.
  • Map detection coverage to established adversary tactics, techniques, and procedures.
  • Use frameworks such as MITRE ATT&CK to identify detection gaps and prioritize improvements.
  • Develop behavioral and analytics-based detections for suspicious activity and anomalous behavior.
  • Analyze security telemetry from SIEM, EDR, XDR, NDR, IDS/IPS, firewalls, identity platforms, cloud services, applications, and other security tools.
  • Develop and optimize SIEM correlation rules, queries, alerts, and detection logic.
  • Create advanced queries using relevant security-query languages and analytics platforms.
  • Tune detection rules to improve signal quality and reduce false positives.
  • Investigate recurring alerts and identify opportunities for improved detection precision.
  • Establish detection thresholds, suppression logic, enrichment, prioritization, and alert-routing mechanisms.
  • Develop detection logic for known indicators of compromise and emerging attack patterns.
  • Incorporate threat-intelligence indicators, behavioral patterns, and adversary techniques into detection capabilities.
  • Monitor threat-intelligence feeds and assess their relevance to the organization's technology environment.
  • Conduct proactive threat hunting to identify previously undetected malicious activity.
  • Develop threat-hunting hypotheses based on threat intelligence, incidents, vulnerabilities, and observed attacker behavior.
  • Investigate anomalous activity across endpoints, identities, networks, cloud environments, and applications.
  • Perform retrospective searches across historical security telemetry to identify potential compromise.
  • Support incident-response teams by developing detection queries, investigative searches, and technical indicators.
  • Analyze security incidents to identify detection opportunities and improve future prevention and monitoring.
  • Conduct post-incident detection reviews and implement lessons learned.
  • Develop detections for newly discovered vulnerabilities, exploits, malware families, and attack campaigns.
  • Assess security alerts generated by new technologies, applications, infrastructure, and cloud services.
  • Establish detection requirements for new systems before production deployment.
  • Work with engineering teams to ensure appropriate security logging and telemetry are available.
  • Identify missing, incomplete, or low-quality security telemetry and coordinate remediation.
  • Define log-source onboarding requirements, parsing standards, normalization, and data-quality expectations.
  • Validate that critical security events are correctly collected, normalized, enriched, and searchable.
  • Develop detection content for Windows, Linux, macOS, network devices, cloud platforms, containers, and enterprise applications where applicable.
  • Develop identity-focused detections covering suspicious authentication, privilege escalation, credential abuse, impossible travel, anomalous access, and account compromise.
  • Develop cloud-security detections covering unusual API activity, privilege changes, suspicious resource creation, credential misuse, and abnormal access patterns.
  • Develop endpoint detections for suspicious processes, scripts, command execution, persistence mechanisms, and malicious behavior.
  • Develop network detections for unusual connections, command-and-control activity, scanning, lateral movement, and data exfiltration.
  • Develop application and database detections for suspicious administrative activity, abnormal access, injection attempts, and unauthorized data access.
  • Evaluate detection effectiveness through controlled testing, purple-team exercises, simulations, and attack emulation.
  • Collaborate with penetration testing, red-team, vulnerability-management, and security-engineering teams to improve detection coverage.
  • Develop detection test cases and validation procedures for critical detection rules.
  • Monitor detection performance and investigate detections that fail to identify known attack scenarios.
  • Maintain detection content through controlled versioning, peer review, testing, deployment, and retirement processes.
  • Establish detection-development standards, documentation requirements, naming conventions, and quality controls.
  • Maintain an accurate inventory of detection rules, data sources, coverage areas, owners, dependencies, and review dates.
  • Develop dashboards and reporting covering detection coverage, alert quality, threat activity, and detection performance.
  • Track detection gaps, false positives, false negatives, tuning activities, and remediation progress.
  • Identify opportunities to automate repetitive detection-development, enrichment, investigation, and response activities.
  • Integrate detection platforms with SOAR, case-management, threat-intelligence, ticketing, and security-automation tools.
Key Performance Indicators
  • Threat detection coverage
  • MITRE ATT&CK technique coverage
  • Critical threat detection coverage
  • Detection rule effectiveness
  • True-positive detection rate
  • False-positive rate
  • False-negative rate
  • Alert-to-incident conversion rate
  • Mean time to detect
  • Mean time to triage
  • Mean time to investigate
  • Mean time to escalate
  • Detection alert volume
  • High-severity alert accuracy
  • Detection tuning effectiveness
  • Detection rule review completion
  • Detection rule test coverage
  • Detection validation success rate
  • Threat-hunting activity completion
  • Threat-hunting finding rate
  • Confirmed threat discovery rate
  • Retrospective threat-search coverage
  • Security telemetry coverage
  • Critical log-source onboarding
  • Log-source data quality
  • Security event ingestion reliability
  • Detection content deployment success
  • Detection change failure rate
  • Detection automation coverage
  • Automated enrichment rate
  • SOAR workflow effectiveness
  • Incident-driven detection improvements
  • Detection gap remediation rate
  • Vulnerability-driven detection coverage
  • Emerging-threat detection deployment time
  • New-threat detection response time
  • Cloud detection coverage
  • Endpoint detection coverage
  • Identity detection coverage
  • Network detection coverage
  • Application detection coverage
  • Detection documentation completeness
  • Detection inventory accuracy
  • Detection platform availability
  • Purple-team detection validation results
  • Security stakeholder satisfaction
Ideal Candidate

The successful candidate should have strong experience in threat detection, detection engineering, security operations, threat hunting, cyber defense, security analytics, or incident response, preferably within a complex enterprise, cloud, financial, technology, telecommunications, or highly regulated environment.

The candidate should demonstrate:

  • Strong understanding of cybersecurity threats, attack techniques, and adversary behavior.
  • Proven experience developing and maintaining security detection rules and analytics.
  • Strong knowledge of SIEM, EDR, XDR, NDR, IDS/IPS, firewalls, and security-monitoring technologies.
  • Experience using MITRE ATT&CK or comparable threat-modeling frameworks.
  • Strong detection-engineering and security-query development skills.
  • Experience with SIEM query languages and security analytics platforms.
  • Strong knowledge of Windows, Linux, networking, identity, cloud, and enterprise security technologies.
  • Experience developing behavioral and analytics-based detections.
  • Strong understanding of authentication, privilege escalation, lateral movement, persistence, command-and-control, and data-exfiltration techniques.
  • Experience conducting proactive threat hunting and retrospective security investigations.
  • Strong knowledge of threat intelligence and its application to detection development.
  • Experience analyzing indicators of compromise, attacker behaviors, malware activity, and security telemetry.

Similar jobs

Apply on LinkedIn