Detection Engineer

KAUST (King Abdullah University of Science and Technology)
مكة المكرمة, مكة المكرمة دوام كامل
نشر: 1448/2/1 | 2026/07/15 ينتهي: 1448/3/1 | 2026/08/14 ✨ وصف بالذكاء الاصطناعي
تقدم للوظيفة الآن

الوصف الوظيفي

About the Role

The Detection Engineer plays a pivotal role in strengthening an organization’s cybersecurity posture by designing, developing, and refining advanced threat detection capabilities. This position bridges the gap between threat intelligence and operational security, translating adversary tactics into high-fidelity detection logic that empowers security teams to identify malicious activity with precision. By engineering automated detection content across diverse security platforms—including SIEM, EDR, NDR, and cloud security tools—the Detection Engineer ensures robust coverage against both known and emerging threats while mitigating alert fatigue through continuous tuning and optimization. The role demands a proactive approach to threat hunting, rigorous testing methodologies, and close collaboration with cross-functional teams to enhance detection efficacy and operational resilience.

Key Responsibilities

Detection Development & Engineering

This role involves the end-to-end development of detection rules and alerts tailored to multiple security platforms. The Detection Engineer will:

  • Design, develop, and deploy detection rules across SIEM, EDR, NDR, and cloud security tools to ensure comprehensive coverage.
  • Create high-fidelity detections grounded in threat intelligence, MITRE ATT&CK techniques, and real-time threat landscapes.
  • Author detection logic using specialized query and rule languages, including KQL, SPL, Sigma, YARA, and others, to align with organizational tooling.
  • Develop custom parsers and correlation rules to enhance the interpretability and utility of security event data.
  • Build detections for both indicator-based threats (IOCs) and behavioral or anomaly-based patterns to detect sophisticated attacks.
  • Continuously tune and optimize detection rules to minimize false positives without compromising coverage.

Threat Hunting & Research

The Detection Engineer will proactively identify gaps in detection coverage and contribute to threat intelligence by:

  • Conducting structured threat-hunting campaigns to uncover undetected adversary activity.
  • Analyzing adversary tactics, techniques, and procedures (TTPs) to inform the development of new detections.
  • Researching emerging threats and translating findings into actionable detection content.
  • Formulating hypotheses and leveraging data analytics to validate or refute threat scenarios.
  • Documenting threat-hunting activities, findings, and lessons learned to foster continuous improvement.

Detection Testing & Validation

Ensuring the effectiveness of detection rules requires rigorous testing and validation processes, including:

  • Performing regular testing of detection rules using attack simulations and red-team exercises.
  • Validating detection efficacy against the MITRE ATT&CK framework to ensure alignment with industry standards.
  • Utilizing tools such as Atomic Red Team, CALDERA, or custom scripts to generate realistic test telemetry.
  • Measuring and reporting on detection coverage and key performance indicators (KPIs) to track progress.
  • Conducting purple-team exercises in collaboration with offensive security teams to validate detection logic.

Data Source Engineering

To maximize detection visibility, the Detection Engineer will:

  • Identify and onboard new log sources to expand coverage across critical systems and applications.
  • Ensure log quality, completeness, and normalization to maintain consistency across all data sources.
  • Partner with IT and engineering teams to configure optimal logging and telemetry for detection use cases.
  • Map data sources to MITRE ATT&CK techniques to identify and address coverage gaps.
  • Optimize data-ingestion pipelines to support the evolving needs of detection engineering.

Automation & Tooling

The role emphasizes the development of automation workflows and tools to streamline detection engineering processes, including:

  • Creating automation workflows for detection deployment and management, following a Detection-as-Code approach.
  • Building tools and scripts to enhance the efficiency of detection-engineering tasks.
  • Developing automated response playbooks for common detection scenarios to accelerate incident response.
  • Implementing CI/CD pipelines for detection content to ensure rapid and reliable deployment.
  • Integrating threat-intelligence feeds into detection platforms to enable real-time updates.

ITSM & Operational Management

The Detection Engineer will manage detection-related incidents, requests, and changes through structured ITSM workflows, including:

  • Managing detection-related incidents, requests, and changes via ticketing systems such as ServiceNow or Jira.
  • Documenting detection deployments, modifications, and rollbacks in alignment with change-management processes.
  • Supporting problem management to identify and resolve recurring detection issues.
  • Maintaining accurate CMDB records for detection rules and monitoring infrastructure.
  • Generating reports on detection coverage, effectiveness, and operational performance to inform stakeholders.
  • Ensuring compliance with service-level agreements (SLAs) for detection development and tuning requests.

Collaboration & Knowledge Sharing

Fostering collaboration across teams is essential to the success of this role. The Detection Engineer will:

  • Partner with SOC analysts to refine detections based on operational feedback and real-world incidents.
  • Collaborate with incident-response teams to create detections from post-incident learnings.
  • Work with threat-intelligence teams to operationalize intelligence and enhance detection capabilities.
  • Create and maintain comprehensive detection-engineering documentation and runbooks.
  • Mentor junior detection engineers and SOC analysts to build organizational expertise.

Technical Competencies

To excel in this role, candidates must demonstrate expertise in the following areas:

  • Detection & Query Languages: Proficiency in at least two query languages, such as SPL (Splunk), KQL (Sentinel/Kusto), SQL, or equivalent, with experience authoring detection logic in Sigma, YARA, or similar frameworks.
  • Threat Intelligence: Ability to analyze and operationalize threat intelligence to inform detection strategies.
  • Security Frameworks: Strong understanding of MITRE ATT&CK and other frameworks to guide detection development.
  • Automation & Scripting: Experience with scripting languages (Python, PowerShell, etc.) to build tools and automate workflows.
  • Cloud Security: Familiarity with cloud security tools and platforms (AWS, Azure, GCP) to extend detection capabilities into cloud environments.
  • Data Analysis: Proficiency in data analytics and visualization tools to identify patterns and anomalies.

يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.

المصدر: لينكد إن ↗ • 12 مشاهدة

وظائف مشابهة

تقدم للوظيفة الآن