Detection Engineer - REMOTE
Indexed description
Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.
Responsibilities
- Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
- Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
- Leverage APIs to automate rule deployment, validation, and telemetry inspection—reducing reliance on GUIs.
- Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
- Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
- Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
- Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
- Support documentation of detection logic, coverage rationale, and response guidance.
- Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.
- 2–5+ years of hands-on experience in detection engineering, threat hunting, or incident response.
- Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
- Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.
- Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
- Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.
- Ability to quickly learn new security technologies and adapt detection strategies accordingly.
- Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.
- Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).
- Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).
- Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
- Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.
- Experience in IR consulting and working across diverse EDR/SIEM stacks.
For more information, visit our website, check out our blog, or follow us on LinkedIn.
Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you’re interested in joining a growing team with great perks, we encourage you to apply!
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search