Security Detection Engineer

WPP

Chennai District

Hybrid

INR 1,400,000 - 2,100,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

WPP Detection Engineering is hiring to design, develop, and maintain high‑fidelity detection logic across SIEM, EDR, and cloud platforms. You will automate rule deployment, review detection accuracy, and drive improvements with the SOC, threat hunters, and engineers.

Join a role that emphasizes automation, RCA, and threat-informed defense, aligned with the GCAT SOC10x roadmap and a hybrid work model across global teams.

Qualifications

  • Strong knowledge of SIEM, SOAR, EDR, and cloud security platforms.
  • Proficiency in scripting and automation (Python, PowerShell).
  • Familiarity with detection-as-code principles and CI/CD pipelines.
  • Understanding of MITRE ATT&CK framework and threat-informed defense.
  • Ability to work closely with SOC analysts, threat hunters, and engineers.
  • Skilled in documenting detection logic and RCA outcomes.

Responsibilities

  • Develop, test, and maintain detection rules and logic across SIEM, EDR, NDR, and cloud-native platforms.
  • Regularly review and enhance detection logic to improve accuracy, reduce noise, and align with evolving threats.
  • Work with wider WPP engineering teams to ensure high-quality, normalized telemetry for effective detection.
  • Automate detection rule deployment, QA, and version control using scripting and CI/CD pipelines.
  • Conduct RCA on missed detections, delayed responses, and high-severity incidents.
  • Identify technical and process-level causes of detection failures or inefficiencies.
  • Drive corrective actions based on RCA outcomes (e.g., rule improvements, visibility gaps).
  • Collaborate with SOC, Incident Response, and Threat Hunting teams to operationalize detection improvements.
  • Work with Threat Intelligence teams to integrate emerging TTPs into detection logic.
  • Contribute to purple team exercises by validating detection logic against simulated attack paths.

Skills

SIEM, SOAR, EDR, and cloud security
Scripting & automation (Python, Power
Detection-as-code & CI/CD
MITRE ATT&CK framework
Collaboration with SOC/threat hunters
Documentation of detection logic & RCA

Education

GIAC GCTI/GCFA or equivalent advanced certification

Tools

SIEM
SOAR
EDR
Cloud security platforms

Job description

WPP is the trusted growth partner for the world’s leading brands.

We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company - powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth.

We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise.

Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow.

For more information, visit WPP.com.

Detection Engineering is responsible for designing, developing, and maintaining high-fidelity detection logic across enterprise security platforms. This role focuses on proactive threat detection, automation-first practices, and continuous improvement of detection coverage and accuracy, supporting the WPP SOC transformation into an Autonomic Security Operations model.

What you’ll be doing:
  • Develop, test, and maintain detection rules and logic across SIEM, EDR, NDR, and cloud-native platforms.
  • Regularly review and enhance detection logic to improve accuracy, reduce noise, and align with evolving threats.
  • Work with wider WPP engineering teams to ensure high-quality, normalized telemetry for effective detection.
  • Automate detection rule deployment, QA, and version control using scripting and CI/CD pipelines.
Root Cause Analysis (RCA)
  • Conduct RCA on missed detections, delayed responses, and high-severity incidents.
  • Identify technical and process-level causes of detection failures or inefficiencies.
  • Drive corrective actions based on RCA outcomes (e.g., rule improvements, visibility gaps).
  • Continuous Security Improvement (CSI)
  • Maintain a CSI backlog (detection gaps, telemetry blind spots, false positives to reduce).
  • Analyze detection performance metrics to identify trends and opportunities for improvement.
  • Align detection priorities with business risk and the SOC transformation roadmap.
  • Collaborate with SOC, Incident Response, and Threat Hunting teams to operationalize detection improvements.
  • Work with Threat Intelligence teams to integrate emerging TTPs into detection logic.
  • Contribute to purple team exercises by validating detection logic against simulated attack paths.
Strategic Alignment to GCAT SOC10x
  • 10X People: Continuous learning and knowledge sharing within the team.
  • 10X Process: Embed agile workflows and automation-first principles.
  • 10X Technology: Leverage AI/ML for detection tuning and anomaly detectio.
  • 10X Visibility: Ensure comprehensive telemetry ingestion and observability.
  • 10X Speed: Reduce detection-to-response cycle through orchestration and automation.
What you’ll need:
Technical Expertise
  • Strong knowledge of SIEM, SOAR, EDR, and cloud security platforms.
  • Proficiency in scripting and automation (Python, PowerShell).
  • Familiarity with detection-as-code principles and CI/CD pipelines.
  • Understanding of MITRE ATT&CK framework and threat-informed defense.
  • Ability to work closely with SOC analysts, threat hunters, and engineers.
  • Skilled in documenting detection logic and RCA outcomes.
Certifications (Preferred)
  • GIAC GCTI, GCFA, or equivalent advanced security certifications.
Key Attributes
  • Automation-first mindset with focus on scalability and resilience.
  • Strong analytical and problem-solving skills.
  • Excellent communication and teamwork capabilities.
Who you are:

You're open: we are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working.

You're optimistic: we approach all that we do with confidence: to try the new and to seek the unexpected.

You're extraordinary: We are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day.

What we’ll give you:

Passionate, inspired people - we champion a culture of people that do extraordinary work

Scale and opportunity - we offer the opportunity to create, influence and deliver projects at a scale that is unparalleled in the industry.

Challenging and stimulating work - unique work and the opportunity to join a group of creative problem solvers.

We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we've adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process.

WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Incident Responder
Senior Security Incident Responder

WPP • Chennai District

Hybrid
INR 1,500,000 - 2,600,000
Security Threat Hunting Specialist
Security Threat Hunting Specialist

wpp • India

On-site
INR 900,000 - 1,500,000
Security Automation Engineer
Security Automation Engineer

Wpp • Chennai District

On-site
INR 1,200,000 - 1,800,000
Hybrid work model
Technology Assurance Senior Specialist
Technology Assurance Senior Specialist

WPP • Chennai District

Hybrid
INR 900,000 - 1,200,000
Hybrid work model
Detection and Response Lead
Detection and Response Lead

Lever, Inc. • India

Remote
INR 3,500,000 - 6,000,000
Fully remote in India
Senior IC role with ownership
Global distributed team
AWS & Tooling Platform Lead
AWS & Tooling Platform Lead

WPP • Chennai District

Hybrid
INR 1,800,000 - 3,200,000
Detection And Response Lead
Detection And Response Lead

One Identity • Panna

On-site
INR 4,000,000 - 7,000,000
AI Detection Engineer - SOC Analyst IV
AI Detection Engineer - SOC Analyst IV

Ten Eleven Ventures • Bengaluru

On-site
INR 2,000,000 - 3,000,000
IN_Manager_SOC_Identity Management_ Advisory _Mumbai
IN_Manager_SOC_Identity Management_ Advisory _Mumbai

PwC International • Airoli

On-site
INR 2,000,000 - 4,000,000
AI Detection Engineer - SOC Analyst IV
AI Detection Engineer - SOC Analyst IV

Saviynt • Bengaluru

On-site
INR 2,500,000 - 4,500,000