Sr Detection Engineer II
Jeppesen ForeFlightSenior Security Detection & Automation Engineer
Role Overview
We are looking for a Senior Security Detection & Automation Engineer with 4 to 8 years of hands-on cybersecurity experience.
This role focuses on designing high-quality security detections, building scalable automation, integrating security technologies, and improving the efficiency and effectiveness of security monitoring. This is an core security position, not a Tier 1 or Tier 2 alert-monitoring role.
Key Responsibilities
Detection Engineering
- Design, develop, test, deploy, and maintain security detections across endpoint, identity, cloud, network, email, and application environments.
- Translate threat intelligence, attacker behaviors, threat-hunting findings, and security risks into actionable detection logic.
- Develop behavioral, anomaly-based, and correlation-based detections across multiple data sources.
- Create detection content using Sigma, KQL, SPL, YARA, Suricata, or platform-specific query languages.
- Map detection coverage to MITRE ATT&CK and identify gaps across priority attack techniques and critical assets.
- Tune detections to improve fidelity, reduce false positives, and minimize unnecessary analyst workload.
- Define detection requirements, including data dependencies, logic, severity, confidence, response guidance, and ownership.
- Manage the complete detection lifecycle, from initial development through validation, deployment, maintenance, and retirement.
- Measure detection quality through coverage, precision, alert volume, false-positive rates, and detection performance.
Security Automation
- Design and develop automation for alert enrichment, correlation, prioritization, evidence collection, case creation, and analyst recommendations.
- Automate repetitive Tier 1 and Tier 2 activities to improve analyst capacity and consistency.
- Build integrations between SIEM, EDR, XDR, SOAR, identity, cloud, threat intelligence, vulnerability management, ticketing, and communication platforms.
- Develop reusable scripts, APIs, services, connectors, and automation components using Python, PowerShell, or comparable languages.
- Implement reliable workflows with error handling, retry logic, logging, monitoring, auditability, and failure notifications.
- Apply appropriate access controls, secrets management, testing, approval points, and rollback capabilities.
- Evaluate AI-assisted security workflows with appropriate validation, evidence tracking, security controls, and human oversight.
- Measure automation value through reduced handling time, improved consistency, lower manual effort, and increased analyst capacity.
Detection-as-Code
- Manage detection content through version-controlled detection-as-code practices.
- Build automated pipelines for detection validation, testing, deployment, and rollback.
- Create unit tests, regression tests, and simulation-based tests for detection logic.
- Validate detections against representative attack data and expected business activity.
- Conduct peer reviews of detection rules and automation code.
- Maintain clear documentation covering detection purpose, logic, telemetry requirements, ATT&CK mapping, testing evidence, known limitations, and response guidance.
- Monitor changes to schemas, data sources, APIs, and security platforms that may affect detection or automation reliability.
Security Research and Continuous Improvement
- Research emerging attacker techniques, security technologies, and detection opportunities relevant to the organization.
- Perform threat hunting and controlled attack simulations to validate detection coverage.
- Identify telemetry gaps and work with technology owners to improve security data quality and visibility.
- Develop reusable engineering standards, libraries, templates, and frameworks.
- Review existing alerts and workflows to identify opportunities for tuning, consolidation, or automation.
- Provide technical guidance on detection logic, telemetry interpretation, and automated workflows.
- Convert security risks and control gaps into measurable engineering improvements.
Required Experience
- 4 to 8 years of hands-on cybersecurity experience, with significant exposure to detection engineering, security automation, threat hunting, SOC engineering, or security engineering.
- Demonstrated experience creating, testing, and tuning production security detections.
- Strong experience with at least one enterprise SIEM platform and one EDR or XDR platform.
- Practical scripting or software development experience using Python, PowerShell, or a comparable language.
- Experience building API-based integrations using REST APIs, webhooks, JSON, and structured security data.
- Experience with Git, peer review, automated testing, and controlled deployment practices.
- Strong understanding of endpoint, identity, cloud, network, email, and application security telemetry.
- Working knowledge of MITRE ATT&CK and common adversary behaviors.
- Ability to distinguish malicious activity from expected business and system behavior.
- Ability to convert a security requirement into a tested, maintainable, and measurable engineering solution.