Detection Engineer

Keka Inc.

United Arab Emirates

Remote

AED 240,000 - 360,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CyberGate is seeking an experienced Detection Engineer to build, validate, and continually improve threat detection across managed customer environments. This hands-on role sits at the crossroads of SOC operations, threat intelligence, and security analytics.

You will translate threat intelligence, incidents, and adversary results into testable use cases, map detections to MITRE ATT&CK, and drive automation through CI/CD pipelines in a multi-customer setting.

Qualifications

  • 5–8 years of cybersecurity experience with at least 3 years in detection engineering.
  • Hands-on with enterprise SIEM platforms such as Sentinel, QRadar, Splunk ES, Elastic SIEM, or similar.
  • Advanced query/detection languages: KQL, SPL, SQL, YARA, Sigma; production experience.

Responsibilities

  • Design, develop, test, deploy, tune, and maintain detection rules, correlations, and enrichment across SIEM, XDR, EDR, NDR, UEBA, and cloud platforms.
  • Own the detection lifecycle from intake to retirement through validation and deployment.
  • Translate adversary tactics and threats into testable detection hypotheses and production use cases.
  • Map detections to MITRE ATT&CK and data sources; identify gaps and plan coverage improvements.
  • Create test suites for positive/negative/regression and conduct controlled simulations.
  • Use Git-based workflows and CI/CD for content review, testing, packaging, deployment, rollback, and verification.
  • Automate recurring engineering tasks with Python, PowerShell, Bash, REST APIs, or related tooling.
  • Define telemetry requirements; coordinate with engineering to improve parsing, enrichment, and data quality.
  • Collaborate with SOC analysts to ensure detections include severity, context, guidance, and response recommendations.
  • Maintain auditable documentation of requirements, tests, approvals, versions, and outcomes.

Skills

Detection engineering
SIEM content engineering
Threat hunting
Python
REST APIs
Git
CI/CD
Troubleshooting
Documentation

Tools

Microsoft Sentinel
IBM QRadar
Splunk Enterprise Security
Elastic Security
ArcSight
LogRhythm
Stellar Cyber

Job description

EXPERIENCE 5–8 years ENVIRONMENT Multi-client MSSP ROLE FAMILY Threat Detection & Security Analytics

Build Detections That Matter

CyberGate is seeking an experienced Detection Engineer to build, validate, and continuously improve threat detection capabilities across managed customer environments. You will turn threat intelligence, adversary behavior, incident findings, threat-hunting results, attack simulation outcomes, and customer risk requirements into reliable and scalable security analytics.

This is a hands-on engineering role at the intersection of SOC Operations, Cyber Threat Intelligence, Threat Hunting, DFIR, security engineering, automation, and security data. You will help evolve an intelligence-led SOC through detection-as-code, automated validation, cloud and identity analytics, measurable coverage engineering, and responsible use of AI-assisted tooling.

What You Will Do
  • Design, develop, test, deploy, tune, and maintain detection rules, correlation logic, behavioral analytics, risk-based detections, queries, and enrichment across SIEM, XDR, EDR, NDR, UEBA, and cloud-native security platforms.
  • Own the detection lifecycle from intake and prioritization through design, peer review, validation, approval, deployment, monitoring, tuning, periodic review, and retirement.
  • Translate adversary tactics, techniques, and procedures, threat intelligence, VAPT findings, incidents, and threat-hunting outcomes into testable detection hypotheses and production use cases.
  • Map detections to MITRE ATT&CK and relevant data sources; identify blind spots and develop prioritized, evidence-based coverage improvement plans.
  • Create positive, negative, regression, and performance tests, using representative data, controlled attack simulation, purple-team exercises, and adversary emulation where appropriate.
  • Use Git-based workflows and contribute to CI/CD pipelines for content review, testing, packaging, deployment, rollback, and post-deployment verification.
  • Automate repetitive engineering activities using Python, PowerShell, Bash, REST APIs, platform SDKs, SOAR, or orchestration capabilities.
  • Define telemetry requirements and work with engineering teams to improve parsing, normalization, enrichment, retention, latency, and data quality.
  • Partner with SOC analysts to ensure detections include clear severity, triage context, investigation guidance, known limitations, and response recommendations.
  • Maintain auditable documentation covering requirements, test evidence, approvals, versions, tuning decisions, dependencies, and outcomes.
What You Bring
  • 5–8 years of relevant cybersecurity experience, including at least 3 years in detection engineering, SIEM content engineering, security analytics, threat hunting, SOC engineering, or a closely related discipline.
  • Strong hands-on experience with one or more enterprise SIEM platforms such as Microsoft Sentinel, IBM QRadar, Splunk Enterprise Security, Stellar Cyber, Elastic Security, ArcSight, or LogRhythm.
  • Advanced capability in relevant query or detection languages such as KQL, SPL, AQL, SQL, EQL, Lucene, YARA, or Sigma, with deep practical experience in at least one production ecosystem.
  • Strong understanding of MITRE ATT&CK, attacker tradecraft, threat detection, log analysis, detection limitations, rule tuning, and evidence-based validation.
  • Experience with security telemetry from endpoint, network, identity, email, firewall, DNS, proxy, WAF, cloud control plane, SaaS, and vulnerability platforms.
  • Working proficiency in Python and REST APIs, plus experience with Git, code review, structured testing, JSON/YAML, and CI/CD concepts.
  • Ability to troubleshoot complex cross-platform issues and clearly explain technical decisions to both technical and non-technical stakeholders.
  • Strong documentation, collaboration, prioritization, and evidence-management skills in a multi-customer environment.
Experience That Will Stand Out
  • Detection-as-code, automated detection validation, attack simulation, purple teaming, or adversary emulation.
  • Cloud-native and identity-focused detection engineering across Microsoft 365, Entra ID, Azure, AWS, or Google Cloud.
  • Risk-based alerting, behavioral or entity analytics, security data lakes, or graph-based detection.
  • AI-assisted detection engineering with strong human validation, data protection, and production-control practices.
  • Experience with OT/ICS detection, containers, Kubernetes, DevSecOps telemetry, or complex MSSP/MDR environments.
  • Exposure to regulatory or sector-specific customer requirements in the UAE or GCC.
Preferred Certifications

Certifications are valued but do not replace demonstrated engineering capability. Relevant examples include:

  • Microsoft Certified: Security Operations Analyst Associate, Splunk security credentials, IBM QRadar certifications, or equivalent platform certifications.
  • GIAC Certified Detection Analyst (GCDA), GIAC Certified Intrusion Analyst (GCIA), GIAC Cyber Threat Intelligence (GCTI), or comparable technical certifications.
  • MITRE ATT&CK Defender training, purple-team credentials, or relevant cloud security certifications.
NICE Framework Alignment

The role aligns primarily with the NICE Defensive Cybersecurity Work Role (PD-WRL-001), with supporting alignment to Threat Analysis (PD-WRL-006) and Incident Response (PD-WRL-003).

What Success Looks Like
  • Detections are documented, peer-reviewed, validated, approved, deployed, monitored, and periodically reassessed.
  • Detection and telemetry health are visible, with failures and coverage gaps addressed using measurable evidence.
  • Alert noise is reduced without creating unassessed loss of coverage.
  • Analysts receive practical investigation context, and engineering changes remain fully traceable.
  • Reusable content and automation improve delivery speed while preserving customer-specific controls and quality.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Deriv.com • Dubai

On-site
AED 350,000 - 550,000
Detection Engineer (SIEM / XDR) | Senior Associate 2
Detection Engineer (SIEM / XDR) | Senior Associate 2

PricewaterhouseCoopers Schweiz • United Arab Emirates

On-site
AED 150,000 - 230,000
Expert Engineer/Security Operation Centre
Expert Engineer/Security Operation Centre

e& UAE • Abu Dhabi

On-site
AED 400,000 - 660,000
Detection Engineer: Build Automated Threat Detections
Detection Engineer: Build Automated Threat Detections

Keka Inc. • United Arab Emirates

Remote
AED 240,000 - 360,000
Specialist Cybersecurity Analyst (Emirati Talent)
Specialist Cybersecurity Analyst (Emirati Talent)

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000
Senior Manager - Cyber Security Engineers
Senior Manager - Cyber Security Engineers

Synechron • Abu Dhabi

On-site
AED 350,000 - 650,000
Senior Security Engineer - EDR & NDR
Senior Security Engineer - EDR & NDR

Help AG • Dubai

Hybrid
AED 260,000 - 460,000
Health insurance
Flexible/Hybrid working environment
Senior Specialist – InfoSec Ops Management
Senior Specialist – InfoSec Ops Management

Tanqeeb • Abu Dhabi

On-site
AED 250,000 - 420,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

Tanqeeb • Dubai

On-site
AED 300,000 - 420,000
Lead Consultant - Incident Response (CPX)
Lead Consultant - Incident Response (CPX)

CPX Piceance • Abu Dhabi

On-site
AED 250,000 - 450,000