Cyber Security Engineer – Threat Detection (1401)

Sharp Decisions

Charlotte (NC)

Hybrid

USD 105,000 - 145,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sharp Decisions seeks an experienced detection engineering professional to join a high-performing Security Operations team in Charlotte, NC. The role focuses on building, tuning, and maintaining detections across cloud and on‑prem environments to proactively identify threats and respond effectively.

You will work with analysts, incident responders, threat intelligence, and technology partners to implement detection-as-code, enhance telemetry pipelines, and align coverage with MITRE ATT&CK.

Qualifications

  • Minimum 3 years of direct cybersecurity, detection engineering, SOC engineering, or security analytics experience.

Responsibilities

  • Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness.
  • Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services.
  • Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies.
  • Collaborate with security analysts, incident responders, SOC engineers, and cross-functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond.
  • Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives.
  • Map detections and coverage to relevant frameworks including MITRE ATT&CK to support measurable improvements in monitoring and response capabilities.
  • Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content.
  • Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency.
  • Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements.
  • Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks.
  • Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience

Skills

Cloud & On-Prem
SIEM/UEBA/EDR/SOAR
Detection-as-Code
MITRE ATT&CK
Query Languages
Threat Intelligence
Automation & Scripting
Windows & Linux
Behavioral Analytics
Data Ingestion
Response Playbooks

Job description

Charlotte, NC - Hybrid

W2 Only Mid-Level -

5 to 7 Years

Banking / Financial Services MITRE ATT&CK

Our client is seeking an experienced detection engineering professional to join a high-performing Security Operations team responsible for advancing security monitoring, detection engineering, and cyber defense capabilities within a major financial institution. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. The successful candidate will bring hands-on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.

? Critical Requirements
  • Minimum 3 years of direct cybersecurity, detection engineering, SOC engineering, or security analytics experience
Role Objectives
  • Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness
  • Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services
  • Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies
  • Collaborate with security analysts, incident responders, SOC engineers, and cross‑functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond
  • Develop and fine‑tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives
  • Map detections and coverage to relevant frameworks including MITRE ATT&CK to support measurable improvements in monitoring and response capabilities
  • Use automation, scripting, and detection‑as‑code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content
  • Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency
  • Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements
  • Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks
  • Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience
Qualifications & Skills
  • Cloud & On-Prem Log Analysis
  • SIEM / UEBA / EDR / SOAR
  • Detection-as-Code Pipelines
  • MITRE ATT&CK Framework
  • Query Languages & Data Analysis
  • Threat Intelligence Translation
  • Automation & Scripting
  • Windows & Linux OS
  • Behavioral Analytics
  • Security Telemetry & Correlation
  • Data Lake & Ingestion Pipelines
  • Response Playbook Development
? Additional Experience a Plus
  • Incident response
  • Threat intelligence operations
  • Vulnerability management
  • Security engineering
  • Cloud security
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer
Detection Engineer

Openkyber • Alaska

On-site
USD 120,000 - 160,000
Detection & Mitigation Engineer
Detection & Mitigation Engineer

United States Digital Space LLC • United States

Hybrid
USD 110,000 - 170,000
Equity plan eligibility
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Jobtailor • Washington

On-site
USD 140,000 - 190,000
Incident Detection and Response Engineer
Incident Detection and Response Engineer

Total Quality Logistics • Tampa (FL)

Hybrid
USD 95,000 - 135,000
Performance bonus
Health, dental and vision coverage
401(k) with company match
+2
Detection Engineer III
Detection Engineer III

OU Health • Oklahoma City (OK)

On-site
USD 110,000 - 140,000
PTO
401(k)
Medical and dental plans
Cybersecurity Detection Engineer – AI-Driven Threats - Hybrid
Cybersecurity Detection Engineer – AI-Driven Threats - Hybrid

Page Mechanical Group, Inc. • Vienna (VA)

Hybrid
USD 120,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

EMW Staffing Solutions LLC • Denver (CO)

Hybrid
USD 125,000 - 135,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • San Francisco (CA)

On-site
USD 237,000 - 297,000
Health benefits
Retirement benefits
Learning and development stipend
+2
Security Engineer - Cloud Threat Detection
Security Engineer - Cloud Threat Detection

RoShay Services • Hartford (CT)

Hybrid
USD 140,000 - 210,000
Senior Cybersecurity Manager
Senior Cybersecurity Manager

Amtex Systems Inc • Atlanta (GA)

Hybrid
USD 120,000 - 150,000