Senior Detection Engineer (AI-Augumented)

Procter & Gamble

Warszawa

Hybrid

PLN 260,000 - 380,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Private health care
P&G stock
Saving plans
Sport cards

Job summary

Procter & Gamble is seeking a Senior Detection Engineer to join the InfoSec Cyber Defense Technology team in Warsaw. You will design, tune, and scale SIEM detections, leveraging AI-assisted workflows and detection-as-code practices to improve alert fidelity.

The role focuses on building detection logic across SIEM/data lakes, collaborating with Threat Intelligence and Threat Hunting, and staying ahead of AI-enabled threats. Hybrid work model with flexible in-office days.

Qualifications

  • 5+ years in detection engineering, security operations, or threat detection.
  • Proven experience writing and tuning SIEM detection rules/analytics.
  • Strong understanding of MITRE ATT&CK and its application to detection coverage.
  • Proficiency in Python for automation and tooling.
  • Experience with git-based workflows for security content management.
  • Familiarity with EDR, identity, cloud, network, and proxy log sources.
  • Formal IT degree or equivalent professional experience.
  • Security certifications are a plus.

Responsibilities

  • Design, build, test, and tune detection rules mapped to MITRE ATT&CK.
  • Write detection logic across SIEM and data lake platforms.
  • Manage detection content as code with git-based workflows, PRs, CI/CD.
  • Investigate and suppress false positives using lookup-based architectures.
  • Collaborate with Threat Hunting and Threat Intelligence teams.
  • Monitor emerging threats and rapidly develop detections for new TTPs.
  • Leverage AI agents and LLM-assisted workflows to accelerate development.
  • Use MCP tooling for AI-assisted detection validation.
  • Operate agentic pipelines triaging large rule libraries against live telemetry.
  • Apply AI/ML techniques for anomaly detection and behavior analytics.
  • Stay current on frontier AI threats and translate them into opportunities.
  • Workshop with SOC to improve alert fidelity and reduce noise.
  • Document detection logic, tuning rationales, and suppression decisions.

Skills

Detection engineering
Threat detection
SIEM analytics
Python
Git-based workflows
MITRE ATT&CK
YAML/ Sigma rules
AI/LLM tooling

Education

Bachelor’s degree in Information Systems / IT / Computer Science / Engineering
Certifications: CISSP, CCSP, OSCP, GCDA/GCIA

Tools

Git
Kubernetes
Cloud platforms
MCP servers
GitHub Copilot

Job description

Job Location WARSAW PLANT & GO Job Description The Senior Detection Engineer plays a vital role in InfoSec's Cyber Defense Technology team, responsible for building, tuning, and scaling detection capabilities across enterprise SIEM platforms. This role operates at the intersection of detection engineering and AI — using agentic AI tooling and LLM-assisted workflows to accelerate threat detection development, validation, and coverage analysis. You will work within a threat-informed detection pipeline where intelligence drives what we detect, and AI agents assist in rule creation, validation, and optimization. The role is hands-on: writing detection logic, managing detection-as-code via git, collaborating with Threat Intelligence and Threat Hunting teams, and continuously improving alert fidelity.

How success looks like
  • Your success would be based on operational and project deliverables, which would be reviewed on a quarterly basis.
  • Your manager would provide full-support though continuous mentoring and coaching.
  • Detection rules you write catch real threats and generate minimal noise.
  • You measurably improve alert fidelity (TP rate) and reduce SOC case volume.
  • You operate independently within the detection-as-code workflow (branch > validate > deploy).
  • You leverage AI tooling to work faster — not as a research project, but as a daily force multiplier.
  • Quarterly deliverables reviewed with your manager through continuous mentoring and coaching.
Job Responsibilities
  • Design, build, test, and tune detection rules mapped to MITRE ATT&CK, prioritized by threat intelligence and business risk.
  • Write detection logic across the SIEM and data lake platforms.
  • Manage detection content as code — git-based workflows, PR reviews, CI/CD deployment pipelines.
  • Investigate and suppress false positives systematically using lookup-based architectures.
  • Collaborate with Threat Hunting and Threat Intelligence teams through structured handover processes (TI>TH>DE pipeline).
  • Monitor emerging threats and rapidly develop detections for new TTPs, CVEs, and active campaigns.
  • Leverage AI agents and LLM-assisted workflows to accelerate detection rule development, validation, and coverage analysis.
  • Use and contribute to MCP (Model Context Protocol) tooling that enables AI-assisted detection validation (e.g., querying telemetry, assessing LOLBAS/GTFOBins, checking coverage gaps).
  • Operate agentic pipelines that triage large rule libraries against live telemetry at scale.
  • Apply AI/ML techniques where appropriate for anomaly detection, behavioral analytics, or pattern identification in security datasets.
  • Stay current on frontier AI threats (agentic attacks, LLM-assisted exploitation, AI-generated phishing) and translate them into detection opportunities.
  • Work closely with SOC analysts to understand alert quality feedback and drive fidelity improvements.
  • Collaborate with data engineers on telemetry availability, data quality, and log source onboarding.
  • Contribute to detection coverage reporting and MITRE ATT&CK posture measurement.
  • Document detection logic, tuning rationale, and suppression decisions.
Job Qualifications Technical Competencies and Experience
  • 5+ years in detection engineering, security operations, or threat detection roles.
  • Proven experience writing and tuning SIEM detection rules/analytics (correlation rules, scheduled queries, real-time alerts).
  • Strong understanding of MITRE ATT&CK framework and its application to detection coverage.
  • Proficiency in Python for automation, scripting, and tooling.
  • Experience with git-based workflows (branching, PRs, CI/CD) for managing security content.
  • Familiarity with security log sources: EDR, identity, cloud, network, proxy.
  • Strong analytical skills and ability to distinguish true threats from noise in large datasets.
  • Bachelor’s degree in Information Systems, Information Technology (IT), Computer Science, Engineering, or other technical / IT field and / or at least 5+ years of relevant experience.
  • CISSP, CCSP, OSCP, GIAC Certified Detection Analyst (GCDA), GCIA, Relevant certifications in cloud & ML/AI.
  • Preferred: Experience with multiple query languages.
  • Preferred: Experience with detection-as-code practices and YAML-based rule formats (Sigma, custom schemas).
  • Working knowledge of AI/LLM capabilities and their security implications — both as detection targets and as engineering tools.
  • Experience with MCP servers, GitHub Copilot, or other AI-assisted development workflows.
  • Familiarity with SOAR platforms and their integration with detection pipelines.
  • Understanding of Kubernetes, cloud-native architectures, and OT/ICS environments.

We offer P&G-sized projects and access to world leading IT partners and technologies from Day 1. Wide range of self-development possibilities (training and certifications paths). Competitive starting salary and benefits program (private health care, P&G stock, saving plans, sport cards). Regular salary increases and possible promotions - in line with your results and performance. Opportunity to change role every few years to be in the best place for you and best for P&G.

At Procter & Gamble we embrace a hybrid work model that combines the flexibility of remote work with the collaborative benefits of in-office engagement. Employees can enjoy the option to work from home two days a week while also spending time in the office to foster teamwork and enhance communication.

About us

We produce globally recognized brands and we grow the best business leaders in the industry. With a portfolio of trusted brands as diverse as ours, it is paramount our leaders can lead with courage the vast array of brands, categories and functions. We serve consumers around the world with one of the strongest portfolios of trusted, quality, leadership brands, including Always, Ariel, Gillette, Head & Shoulders, Herbal Essences, Oral-B, Pampers, Pantene, Tampax and more. Our community includes operations in approximately 70 countries worldwide. Visit http://www.pg.com to know more.

We are an equal opportunity employer and value diversity at our company. We do not discriminate against individuals on the basis of race, color, gender, age, national origin, religion, sexual orientation, gender identity or expression, marital status, citizenship, disability, HIV/AIDS status, or any other legally protected factor.

Job Schedule Full time
Job Number R000155626
Job Segmentation Experienced Professionals

P&G was founded over 180 years ago as a simple soap and candle company. Today, we’re the world’s largest consumer goods company and home to iconic, trusted brands that make life a little bit easier in small but meaningful ways. We’ve spanned three centuries thanks to three simple ideas: leadership, innovation and citizenship. The insight, innovation and passion of talented teams has helped us grow into a global company that is governed responsibly and ethically, that is open and transparent, and that supports good causes and protects the environment. This is a place where you can be proud to work and do something that matters.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AI Engineer (Agentic AI)
Senior AI Engineer (Agentic AI)

Procter & Gamble • Warszawa

Hybrid
PLN 280,000 - 560,000
Private health care
PG stock options
Lunch subsidy
+1
Technical Product Owner — Observability Event Management
Technical Product Owner — Observability Event Management

Procter & Gamble • Warszawa

Hybrid
PLN 300,000 - 600,000
Hybrid work model
Private health care
P&G stock
+2
SailPoint Operations Engineer
SailPoint Operations Engineer

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Private health care
P&G stock
+3
Senior Data Engineer - Superior Retail Execution
Senior Data Engineer - Superior Retail Execution

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid work model
Professional development (training and
certifications paths
Senior AI Agent Engineer
Senior AI Agent Engineer

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 260,000
Private health care
P&G stock
Saving plans
+2
Automation QA Engineer
Automation QA Engineer

Procter & Gamble • Warszawa

On-site
PLN 150,000 - 230,000
Private health care
P&G stock
Saving plans
+1
Senior AI Engineer (AI Factory)
Senior AI Engineer (AI Factory)

Procter & Gamble • Warszawa

Hybrid
PLN 250,000 - 380,000
Hybrid work model
In-office fitness center
PG stock options
+1
Data Manager - Digital Workplace and Facilities Services
Data Manager - Digital Workplace and Facilities Services

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Competitive benefits program
Technical Engineering Manager, React, GCP & AI
Technical Engineering Manager, React, GCP & AI

Procter & Gamble • Warszawa

On-site
PLN 149,000 - 179,000
Private health care
PG stock
Saving plans
+2
Platform Customer Success Engineer, Data & AI
Platform Customer Success Engineer, Data & AI

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 240,000