Cybersecurity Detection Engineer x2

Zohorecruit

Charlotte (NC)

Hybrid

USD 105,000 - 155,000

Full time

36 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Axiom Path is recruiting for a threat detection engineer within a global financial services organization in Charlotte, NC. You will design and tune detections across cloud and on-premises environments, collaborate with SOC analysts, threat intelligence, and incident response teams, and continually improve monitoring efficacy.

The role emphasizes automation, detection-as-code, and measurable improvements in alert quality and coverage, with hybrid work in Charlotte, NC.

Qualifications

  • 3+ years in detection engineering, SOC engineering, security analytics, or related field.
  • Hands-on with logs/telemetry from endpoint, network, identity, cloud, and infrastructure.
  • Experience with SIEM, UEBA, EDR, SOAR or similar security-monitoring tech.
  • Strong knowledge of security query languages and data-analysis methods.
  • Experience building automation, scripts, and detection-as-code pipelines.
  • Ability to map threat intelligence and attacker behaviours to practical detections.
  • Experience mapping detections to MITRE ATT&CK framework.
  • Clear written and verbal communication; can document detection logic clearly.

Responsibilities

  • Design, develop, test, tune, and maintain threat detection logic across cloud and on-premises environments.
  • Improve alert quality, monitoring visibility, and detection capabilities.
  • Build and maintain data onboarding for endpoint, network, identity, cloud telemetry.
  • Translate threat intel into actionable monitoring use cases.
  • Develop correlation rules, signatures, and thresholds to reduce false positives.
  • Collaborate with SOC analysts to investigate alerts and close gaps.
  • Map detection logic to MITRE ATT&CK and related frameworks.
  • Apply automation and detection-as-code to improve scalability.

Skills

Threat detection
Security analytics
SOC engineering
Automation
MITRE ATT&CK
Log analysis
Scripting
Incident response

Tools

SIEM
UEBA
EDR
SOAR

Job description

Charlotte, United States | Posted on 10/05/2026

Axiom Path is an AI-first recruiting and staffing firm delivering RPO, MSP, and direct-hire solutions to enterprise clients across the U.S. Our team of experienced recruiters, supported by purpose-built automation, moves faster and communicates better so clients get qualified talent sooner and candidates get a clear, responsive process from first contact to start date.

Job Description
Be Part of a High-Performing Team

Join a global financial services organization committed to maintaining resilient, secure, and highly regulated technology operations. The cybersecurity organization protects complex cloud and on-premises environments by strengthening monitoring, threat detection, and incident response capabilities.

This position supports a collaborative Security Operations team that works closely with SOC analysts, incident responders, threat intelligence specialists, security engineers, and technology partners. The environment is fast-paced and analytical, with a strong emphasis on measurable detection coverage, automation, operational excellence, and continuous improvement.

What s In Store For You
  • Engagement: W2 only; no C2C or 1099 arrangements.
  • Hybrid position based in Charlotte, North Carolina.
  • Opportunity to develop sophisticated threat detections across cloud and on-premises environments.
  • Exposure to security analytics, detection-as-code, automation, MITRE ATT&CK, and modern security monitoring technologies.
  • Collaboration with global cybersecurity, threat intelligence, incident response, and technology teams.
  • Opportunity to directly improve the organization s ability to identify and respond to emerging cyber threats.
How You Will Make an Impact
  • Design, develop, test, tune, and maintain threat detection logic across cloud and on-premises environments.
  • Improve alert quality, monitoring visibility, and the organization s ability to detect and respond to malicious activity.
  • Build and maintain log onboarding and data-ingestion processes for endpoint, network, identity, cloud, application, and infrastructure telemetry.
  • Translate threat intelligence, attacker behaviors, and indicators of compromise into actionable monitoring use cases.
  • Develop correlation rules, behavioral analytics, signatures, alert thresholds, and detection content that reduce false positives.
  • Partner with SOC analysts and incident responders to investigate alerts, validate detection effectiveness, and identify coverage gaps.
  • Map detection logic and security-monitoring coverage to the MITRE ATT&CK framework.
  • Apply scripting, automation, and detection-as-code practices to improve testing, deployment, scalability, and lifecycle management.
  • Evaluate security data sources, analytics capabilities, and monitoring technologies to identify opportunities for improvement.
  • Ensure detection-engineering practices align with regulatory obligations, internal controls, and cybersecurity standards.
  • Assess the effectiveness of monitoring controls and recommend practical improvements that strengthen cyber resilience.
Requirements
Do You Bring Proven Success in Threat Detection and Security Analytics?
  • At least 3 years of experience in detection engineering, SOC engineering, security analytics, cybersecurity operations, or a related discipline.
  • Hands-on experience analyzing logs and telemetry from endpoint, network, identity, cloud, infrastructure, and application platforms.
  • Experience working with SIEM, UEBA, EDR, SOAR, security data lakes, or comparable security-monitoring technologies.
  • Strong knowledge of security query languages and data-analysis methods used to investigate events and build detection logic.
  • Experience developing automation, scripts, detection-as-code pipelines, or repeatable security operations processes.
  • Ability to convert threat intelligence, adversary behaviors, and attack techniques into practical detections.
  • Experience mapping detections or security coverage to MITRE ATT&CK or a similar framework.
  • Working knowledge of Windows, Linux, enterprise infrastructure, and cloud environments.
  • Strong troubleshooting, analytical, and root-cause analysis capabilities.
  • Ability to independently manage operational responsibilities and project deliverables.
  • Clear written and verbal communication skills, including the ability to document technical detection logic and tuning decisions.
  • Strong ownership, attention to detail, and the ability to collaborate effectively within a global team.
  • Experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Program Manager
Senior Cybersecurity Program Manager

Zohorecruit • Charlotte (NC)

Remote
USD 120,000 - 150,000
Help Desk & User Outreach Analyst Data Protection Remediation Support x2
Help Desk & User Outreach Analyst Data Protection Remediation Support x2

Zohorecruit • Charlotte (NC)

Hybrid
USD 45,000 - 65,000
Hybrid Threat Detection Engineer (Charlotte)
Hybrid Threat Detection Engineer (Charlotte)

Zohorecruit • Charlotte (NC)

Hybrid
USD 105,000 - 155,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Sigma Software • United States

Remote
USD 110,000 - 150,000
Information Security Analyst - Hybrid
Information Security Analyst - Hybrid

Commscope Holding • Honolulu (HI)

On-site
USD 110,000 - 140,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Cybersecurity Jobs • Kansas City (MO)

Hybrid
USD 120,000 - 190,000
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Detection & Response Engineering Manager
Detection & Response Engineering Manager

Objective Partners • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+4
Manager
Manager

Torsap Thai Kitchen • Berkeley (CA)

On-site
USD 140,000 - 175,000
Health insurance
Dental insurance
Vision insurance
+4