Jeppesen ForeFlight logo

Sr Detection Engineer II

Jeppesen ForeFlight
Posted 1 hour ago
SwedenHybridEngineering & Development
Is this job info correct?

Senior Security Detection & Automation Engineer

Role Overview

We are looking for a Senior Security Detection & Automation Engineer with 4 to 8 years of hands-on cybersecurity experience.

This role focuses on designing high-quality security detections, building scalable automation, integrating security technologies, and improving the efficiency and effectiveness of security monitoring. This is an core security position, not a Tier 1 or Tier 2 alert-monitoring role.

Key Responsibilities

Detection Engineering

  • Design, develop, test, deploy, and maintain security detections across endpoint, identity, cloud, network, email, and application environments.
  • Translate threat intelligence, attacker behaviors, threat-hunting findings, and security risks into actionable detection logic.
  • Develop behavioral, anomaly-based, and correlation-based detections across multiple data sources.
  • Create detection content using Sigma, KQL, SPL, YARA, Suricata, or platform-specific query languages.
  • Map detection coverage to MITRE ATT&CK and identify gaps across priority attack techniques and critical assets.
  • Tune detections to improve fidelity, reduce false positives, and minimize unnecessary analyst workload.
  • Define detection requirements, including data dependencies, logic, severity, confidence, response guidance, and ownership.
  • Manage the complete detection lifecycle, from initial development through validation, deployment, maintenance, and retirement.
  • Measure detection quality through coverage, precision, alert volume, false-positive rates, and detection performance.

Security Automation

  • Design and develop automation for alert enrichment, correlation, prioritization, evidence collection, case creation, and analyst recommendations.
  • Automate repetitive Tier 1 and Tier 2 activities to improve analyst capacity and consistency.
  • Build integrations between SIEM, EDR, XDR, SOAR, identity, cloud, threat intelligence, vulnerability management, ticketing, and communication platforms.
  • Develop reusable scripts, APIs, services, connectors, and automation components using Python, PowerShell, or comparable languages.
  • Implement reliable workflows with error handling, retry logic, logging, monitoring, auditability, and failure notifications.
  • Apply appropriate access controls, secrets management, testing, approval points, and rollback capabilities.
  • Evaluate AI-assisted security workflows with appropriate validation, evidence tracking, security controls, and human oversight.
  • Measure automation value through reduced handling time, improved consistency, lower manual effort, and increased analyst capacity.

Detection-as-Code

  • Manage detection content through version-controlled detection-as-code practices.
  • Build automated pipelines for detection validation, testing, deployment, and rollback.
  • Create unit tests, regression tests, and simulation-based tests for detection logic.
  • Validate detections against representative attack data and expected business activity.
  • Conduct peer reviews of detection rules and automation code.
  • Maintain clear documentation covering detection purpose, logic, telemetry requirements, ATT&CK mapping, testing evidence, known limitations, and response guidance.
  • Monitor changes to schemas, data sources, APIs, and security platforms that may affect detection or automation reliability.

Security Research and Continuous Improvement

  • Research emerging attacker techniques, security technologies, and detection opportunities relevant to the organization.
  • Perform threat hunting and controlled attack simulations to validate detection coverage.
  • Identify telemetry gaps and work with technology owners to improve security data quality and visibility.
  • Develop reusable engineering standards, libraries, templates, and frameworks.
  • Review existing alerts and workflows to identify opportunities for tuning, consolidation, or automation.
  • Provide technical guidance on detection logic, telemetry interpretation, and automated workflows.
  • Convert security risks and control gaps into measurable engineering improvements.

Required Experience

  • 4 to 8 years of hands-on cybersecurity experience, with significant exposure to detection engineering, security automation, threat hunting, SOC engineering, or security engineering.
  • Demonstrated experience creating, testing, and tuning production security detections.
  • Strong experience with at least one enterprise SIEM platform and one EDR or XDR platform.
  • Practical scripting or software development experience using Python, PowerShell, or a comparable language.
  • Experience building API-based integrations using REST APIs, webhooks, JSON, and structured security data.
  • Experience with Git, peer review, automated testing, and controlled deployment practices.
  • Strong understanding of endpoint, identity, cloud, network, email, and application security telemetry.
  • Working knowledge of MITRE ATT&CK and common adversary behaviors.
  • Ability to distinguish malicious activity from expected business and system behavior.
  • Ability to convert a security requirement into a tested, maintainable, and measurable engineering solution.

Similar jobs