Security Detection Engineer III

F5

Warszawa

On-site

PLN 180,000 - 260,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

F5 is seeking a seasoned Security Engineer to design and maintain advanced detections, aligned with MITRE ATT&CK, across SIEM/EDR platforms. You will collaborate with Incident Response, Threat Intelligence, and Logging teams to translate evolving threats into actionable content.

The role emphasizes automation, rigorous testing, and on-call coverage, with travel up to 5% as needed. A strong foundation in detections and AI-enabled security is essential.

Qualifications

  • Bachelor's degree or equivalent practical experience in information security or related field.
  • 5+ years of cybersecurity, security engineering, detection engineering, or related roles.
  • Experience developing, tuning, or maintaining detections in SIEM/EDR/log analytics.
  • Scripting/automation using Python, PowerShell, SQL, KQL, or SPL.
  • Strong understanding of attacker techniques and MITRE ATT&CK.
  • Excellent analytical, problem-solving, and cross-functional communication skills.

Responsibilities

  • Develop and maintain custom detections with Detection-as-Code practices, including version control, reviews, testing, and CI/CD workflows.
  • Map telemetry/detections to adversary behaviors and MITRE ATT&CK to improve coverage.
  • Collaborate with Incident Response, Threat Intelligence, Logging Engineering, and security platform teams to translate threats into actionable content.
  • Tune detections via adversary emulation, purple-team exercises, and production feedback to reduce false positives.
  • Automate detection engineering workflows and alert enrichment to improve efficiency and scalability.
  • Onboard new log sources and establish coverage across environments and technologies.
  • Create and maintain detection docs, runbooks, coverage assessments, and standards; participate in on-call rotation.
  • Define detection strategy for AI/agentic systems and explore AI to accelerate workflows.

Skills

5+ years in cybersecurity
SIEM/EDR/detection engineering
Python/PowerShell/SQL/KQL
MITRE ATT&CK framework
cross-functional collaboration

Education

Bachelor's degree in Information Security or related field

Tools

SIEM
EDR
Splunk
Microsoft Sentinel
CrowdStrike
Elastic

Job description

At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.

Everything we do centers around people. That means we obsess over how to make the lives of our customers, and their customers, better. And it means we prioritize a diverse F5 community where each individual can thrive.

Primary Responsibilities
  • Develop and maintain custom detections using Detection-as-Code practices, including version control, peer review, testing, and CI/CD deployment workflows.
  • Analyze and improve detection coverage by mapping telemetry and detections to adversary behaviors and the MITRE ATT&CK framework, identifying gaps and prioritizing enhancements.
  • Partner with Incident Response, Threat Intelligence, Logging Engineering, and security platform teams to translate emerging threats, investigations, and telemetry into actionable detection content.
  • Validate and tune detections through adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality and reduce false positives.
  • Automate and optimize detection engineering workflows, alert enrichment processes, and operational activities to improve efficiency and scalability.
  • Support onboarding of new log sources and security telemetry by collaborating with engineering and infrastructure teams to establish detection coverage across new environments and technologies.
  • Create and maintain detection documentation, runbooks, coverage assessments, and technical standards while participating in an engineering on-call rotation.
  • Help define detection strategy for AI and agentic systems (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs), and explore using AI to accelerate detection engineering workflows.
Required Skills / Qualifications
  • Bachelor's degree in Information Security, Computer Science, Engineering, or related field, or equivalent practical experience.
  • 5+ years of experience in cybersecurity, security engineering, detection engineering, security operations, threat hunting, or a related discipline.
  • Experience developing, tuning, or maintaining detections within a SIEM, EDR, log analytics, or security monitoring platform.
  • Experience with scripting, automation, or data analysis using Python, PowerShell, SQL, KQL, SPL, or similar technologies.
  • Strong understanding of attacker techniques, detection methodologies, and frameworks such as MITRE ATT&CK.
  • Strong analytical, problem-solving, communication, and cross-functional collaboration skills.
Preferred Skills / Qualifications
  • Experience implementing Detection-as-Code practices, including Git-based workflows, automated testing, and CI/CD pipelines.
  • Experience with adversary emulation, atomic testing, purple-team exercises, or detection validation frameworks.
  • Experience performing detection coverage analysis and developing ATT&CK-based coverage roadmaps.
  • Experience onboarding log sources and building detections across cloud, endpoint, network, identity, or SaaS environments.
  • Experience with platforms such as CrowdStrike, Splunk, Microsoft Sentinel, Chronicle, Elastic, or similar security technologies.
  • Familiarity with AI/LLM threat models (prompt injection, tool and function abuse, agent identity and credential misuse, data exfiltration via model outputs) or frameworks such as MITRE ATLAS and the OWASP LLM Top 10 — and interest in applying AI to accelerate detection engineering workflows.
Work Environment

This is a full-time engineering role and is not a shift-based position. Participation in an engineering on-call rotation is required and may occasionally require support outside normal business hours during critical incidents, platform outages, or detection-related operational events. The Security Engineer III may be engaged as a subject matter expert during security incidents but is not responsible for primary incident response or SOC operations. Travel may be required up to 5%, including occasional international travel.

The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change.

Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com).

Equal Employment Opportunity

It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Detection Engineer III
Security Detection Engineer III

F5 Networks • Poland

On-site
PLN 180,000 - 300,000
Security Detection Engineer III
Security Detection Engineer III

F5 Networks, Inc.  • Warszawa

On-site
PLN 180,000 - 240,000
Red Team - Security Researcher III
Red Team - Security Researcher III

F5 • Warszawa

On-site
PLN 180,000 - 280,000
Senior Threat Hunter & Security Researcher
Senior Threat Hunter & Security Researcher

F5 • Warszawa

On-site
PLN 180,000 - 280,000
Senior Security Engineer, AI & Automation
Senior Security Engineer, AI & Automation

F5 Networks • Poland

On-site
PLN 250,000 - 450,000
Senior Security Engineer, AI & Automation
Senior Security Engineer, AI & Automation

F5 • Warszawa

On-site
PLN 240,000 - 300,000
Senior Security Engineer
Senior Security Engineer

F5 • Warszawa

On-site
PLN 180,000 - 240,000
SecOps Platform Engineer III (DLP/EDR)
SecOps Platform Engineer III (DLP/EDR)

F5 • Warszawa

On-site
PLN 140,000 - 210,000
Senior Security Engineer
Senior Security Engineer

F5, Inc. • Poland

On-site
PLN 80,000 - 100,000
Senior Security Engineer
Senior Security Engineer

F5 Networks, Inc.  • Warszawa

Hybrid
PLN 530,000 - 682,000