Senior Detection Engineer (AI-Augumented)

Procter & Gamble

Poland

On-site

PLN 240,000 - 360,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

P&G-sized projects
Self-development opportunities
Competitive salary & benefits

Job summary

Procter & Gamble Warsaw Plant is seeking a Senior Detection Engineer to build, tune, and scale detection across enterprise SIEM platforms, integrating AI-assisted workflows.

You will write detection logic, manage content as code with Git, collaborate with Threat Intelligence and Threat Hunting, and improve alert fidelity and coverage.

The role combines detection engineering with AI tooling to speed up development, validation, and deployment while maintaining noise reduction.

Qualifications

  • 5+ years in detection engineering, security operations, or threat detection roles.
  • Proven experience writing and tuning SIEM detection rules/analytics.
  • Strong understanding of MITRE ATT&CK and its application to detection.
  • Proficiency in Python for automation and tooling.
  • Experience with git-based workflows for managing security content.
  • Familiarity with security log sources: EDR, identity, cloud, network, proxy.

Responsibilities

  • Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intel and risk.
  • Write detection logic across SIEM and data lake platforms.
  • Manage detection content as code – git-based workflows, PRs, CI/CD pipelines.
  • Investigate and suppress false positives using lookup-based architectures.
  • Collaborate with Threat Hunting and Threat Intelligence teams.
  • Monitor emerging threats and rapidly develop detections for new TTPs and campaigns.
  • Leverage AI agents to accelerate detection validation and deployment.

Skills

Detection engineering
SIEM detection rules
MITRE ATT&CK
Python automation
Git-based workflows
Security log sources
Analytical skills
Bachelor degree (IT/CS/Engineering)

Education

Bachelor's degree in Information Systems/IT/CS/Engineering

Tools

Python
Git
Sigma / YAML rule formats
MCP tooling
GitHub Copilot
SOAR platforms
Kubernetes

Job description

Job Location

WARSAW PLANT & GO

Job Description

The Senior Detection Engineer plays a vital role in InfoSec's Cyber Defense Technology team, responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms. This role operates at the intersection of detection engineering and AI - using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development, validation, and coverage analysis.

You will work within a threat-informed detection pipeline where intelligence drives what we detect, and AI agents assist in rule creation, validation, and optimization. The role is hands‑on: writing detection logic, managing detection-as-code via git, collaborating with Threat Intelligence and Threat Hunting teams, and continuously improving alert fidelity.

How success looks like

Your success would be based on operational and project deliverables, which would be reviewed on a quarterly basis. Your manager would provide full-support though continuous mentoring and coaching

  • Detection rules you write catch real threats and generate minimal noise
  • You measurably improve alert fidelity (TP rate) and reduce SOC case volume
  • You operate independently within the detection-as-code workflow (branch → validate → deploy)
  • You leverage AI tooling to work faster - not as a research project, but as a daily force multiplier
  • Quarterly deliverables reviewed with your manager through continuous mentoring and coaching
Job Responsibilities
  • Detection Engineering (Core):
    • Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intelligence and business risk
    • Write detection logic across the SIEM and data lake platforms
    • Manage detection content as code – git‑based workflows, PRs, CI/CD deployment pipelines
    • Investigate and suppress false positives systematically using lookup‑based architectures
    • Collaborate with Threat Hunting and Threat Intelligence teams through structured handover processes (TI→TH→DE pipeline)
    • Monitor emerging threats and rapidly develop detections for new TTPs, CVEs, and active campaigns
  • AI‑Augmented Detection (Differentiator):
    • Leverage AI agents and LLM‑assisted workflows to accelerate detection rule development, validation, and coverage analysis
    • Use and contribute to MCP (Model Context Protocol) tooling that enables AI‑assisted detection validation (e.g., querying telemetry, assessing LOLBAS/GTFOBins, checking coverage gaps)
    • Operate agentic pipelines that triage large rule libraries against live telemetry at scale
    • Apply AI/ML techniques where appropriate for anomaly detection, behavioral analytics, or pattern identification in security datasets
    • Stay current on frontier AI threats (agentic attacks, LLM‑assisted exploitation, AI‑generated phishing) and translate them into detection opportunities
  • Collaboration & Operations:
    • Work closely with SOC analysts to understand alert quality feedback and drive fidelity improvements
    • Collaborate with data engineers on telemetry availability, data quality, and log source onboarding
    • Contribute to detection coverage reporting and MITRE ATT&CK posture measurement
    • Document detection logic, tuning rationale, and suppression decisions
Job Qualifications
Technical Competencies and Experience
  • Required:
    • 5+ years in detection engineering, security operations, or threat detection roles
    • Proven experience writing and tuning SIEM detection rules/analytics (correlation rules, scheduled queries, real‑time alerts)
    • Strong understanding of MITRE ATT&CK framework and its application to detection coverage
    • Proficiency in Python for automation, scripting, and tooling
    • Experience with git‑based workflows (branching, PRs, CI/CD) for managing security content
    • Familiarity with security log sources: EDR, identity, cloud, network, proxy
    • Strong analytical skills and ability to distinguish true threats from noise in large datasets
    • Bachelor's degree in Information Systems, Information Technology (IT), Computer Science, Engineering, or other technical / IT field and / or at least 5+ years of relevant experience.
    • Certification *Preferred* Requirements: CISSP, CCSP, OSCP, GIAC Certified Detection Analyst (GCDA), GCIA, Relevant certifications in cloud & ML/AI
  • Preferred:
    • Experience with multiple query languages
    • Experience with detection‑as‑code practices and YAML‑based rule formats (Sigma, custom schemas)
    • Working knowledge of AI/LLM capabilities and their security implications – both as detection targets and as engineering tools
    • Experience with MCP servers, GitHub Copilot, or other AI‑assisted development workflows
    • Familiarity with SOAR platforms and their integration with detection pipelines
    • Understanding of Kubernetes, cloud‑native architectures, and OT/ICS environments
We offer
  • P&G-sized projects and access to world leading IT partners and technologies from Day 1.
  • Wide range of self‑development possibilities (training and certifications paths).
  • Competitive starting salary and benefits program
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Product Manager - AI SIEM, Detection and Response
Staff Product Manager - AI SIEM, Detection and Response

SentinelOne • Poland

On-site
PLN 240,000 - 340,000
RSUs
ESPP
Leave benefits
+6
AI-Driven Detection Engineer for SIEM & Threat Analytics
AI-Driven Detection Engineer for SIEM & Threat Analytics

Procter & Gamble • Poland

On-site
PLN 240,000 - 360,000
P&G-sized projects
Self-development opportunities
Competitive salary & benefits
Security Detection Engineer
Security Detection Engineer

SoftServe • Poland

On-site
PLN 180,000 - 280,000
Senior AI-Driven Detection Engineer (SIEM)
Senior AI-Driven Detection Engineer (SIEM)

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 260,000
Private health care
P&G stock
Saving plans
+1
Security Detection Engineer III
Security Detection Engineer III

F5 Networks, Inc.  • Warszawa

Hybrid
PLN 260,000 - 380,000
Security Engineer - Detection Engineering and Threat Modeling
Security Engineer - Detection Engineering and Threat Modeling

Hitachi, Ltd. • Poland

On-site
PLN 110,000 - 140,000
Security Analyst Incident Response & Threat Intelligence
Security Analyst Incident Response & Threat Intelligence

Infotree Global Solutions • Poland

Hybrid
PLN 70,000 - 90,000
Senior Detection Engineer – MITRE ATT&CK & Automation
Senior Detection Engineer – MITRE ATT&CK & Automation

F5 Networks, Inc.  • Warszawa

Hybrid
PLN 260,000 - 380,000
Senior Cyber Security Analyst - EMEA
Senior Cyber Security Analyst - EMEA

Internetwork Expert • Warszawa

On-site
PLN 218,978 - 364,964
Flexible Working Hours
Remote Work
Modern Development Workflows
+2
CyberSecurity Specialist
CyberSecurity Specialist

SEIDOR • Warszawa

On-site
PLN 180,000 - 240,000