Detection Engineer

Openkyber

Alaska

On-site

USD 120,000 - 160,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Openkyber in the United States seeks a Cyber Security Engineer - Threat Detection to join a high-performing Security Operations team responsible for advancing monitoring, detection engineering, and cyber defense capabilities across cloud and on‑prem environments. You will build, tune, and maintain detections to help proactively identify, investigate, and respond to threats.

The role requires hands-on experience with security telemetry, analytics, automation, and detection-as-code, with

Qualifications

  • Minimum 3 years in cybersecurity, detection engineering, SOC, or security ops.
  • Hands-on experience analyzing logs and telemetry from multiple sources (endpoint, network, cloud, identity).

Responsibilities

  • Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness.
  • Build and maintain data ingestion and log onboarding pipelines for security telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services.
  • Collaborate with security analysts, incident responders, SOC engineers, and cross-functional teams to investigate detections, validate coverage, and reduce time to detect and respond.
  • Develop and fine-tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to reduce false positives.
  • Map detections to MITRE ATT&CK and other frameworks to support measurable monitoring improvements.
  • Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of content.
  • Evaluate security monitoring technologies and data sources to identify opportunities to enhance coverage and efficiency.
  • Ensure detection practices align with compliance and internal control requirements.
  • Create and maintain documentation for detection logic, data sources, tuning decisions, procedures, and playbooks.
  • Continuously assess monitoring effectiveness and recommend improvements to strengthen cyber resilience.

Skills

Threat detection
Detection engineering
SOC engineering
Security analytics
Log analysis
Cloud security
Windows
Linux
Scripting
Automation
MITRE ATT&CK
Detection-as-code
Incident response
Threat intelligence

Tools

Cloud SIEM
UEBA
EDR
SOAR
Data lake

Job description

\"We only Accept Local Candidate\" ( North Carolina ) Description Seeking a Cyber Security Engineer - Threat Detection to join a high-performing Security Operations team responsible for advancing the Bank's security monitoring, detection engineering, and cyber defense capabilities. This role focuses on building, tuning, and maintaining effective detections across cloud and on-premises environments to help proactively identify, investigate, and respond to threats before they impact the organization. The successful candidate will bring hands‑on experience with security telemetry, analytics, automation, and detection-as-code practices, and will be expected to execute detection engineering activities with limited guidance while collaborating closely with analysts, incident responders, threat intelligence, and technology partners.




Role Objectives:


  • Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness.

  • Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry from infrastructure, applications, endpoints, identity platforms, and cloud services. Partner with threat intelligence teams to translate emerging threats, attacker techniques, and indicators of compromise into actionable detection strategies.

  • Collaborate with security analysts, incident responders, SOC engineers, and cross‑functional technology teams to investigate detections, validate coverage, and reduce time to detect and respond.

  • Develop and fine‑tune detection rules, signatures, correlation logic, behavioral analytics, and alerting thresholds to improve fidelity and reduce false positives.

  • Map detections and coverage to relevant frameworks, including MITRE ATT&CK, to support measurable improvements in monitoring and response capabilities.

  • Use automation, scripting, and detection-as-code practices to improve consistency, scalability, testing, deployment, and lifecycle management of detection content.

  • Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities to enhance detection coverage and operational efficiency.

  • Ensure detection engineering practices align with applicable compliance, regulatory, and internal control requirements.

  • Create and maintain clear documentation for detection logic, data sources, tuning decisions, operational procedures, and response playbooks.

  • Continuously assess the effectiveness of cybersecurity monitoring controls and recommend improvements to strengthen cyber resilience.




Qualifications and Skills


  • Minimum of 3 years of relevant cybersecurity, detection engineering, SOC engineering, security analytics, or security operations experience.

  • Hands‑on experience analyzing logs and security telemetry from multiple sources, including endpoint, network, identity, cloud, infrastructure, and application platforms.

  • Experience with cloud SIEM, UEBA, EDR, SOAR, data lake, or related detection and monitoring technologies.

  • Strong knowledge of query languages and data analysis techniques used to investigate security events and develop detection logic.

  • Experience developing detection-as-code pipelines, automation, scripts, or repeatable processes to improve security operations efficiency.

  • Ability to translate threat intelligence, adversary behaviors, and attack techniques into practical detections and monitoring use cases.

  • Experience mapping detections to MITRE ATT&CK or similar security frameworks.

  • Working knowledge of Windows and Linux operating systems, common enterprise infrastructure, and cloud environments.

  • Strong troubleshooting, analytical, and problem‑solving skills, with the ability to identify root cause and recommend practical improvements.

  • Ability to balance operational responsibilities with project delivery in a fast‑paced environment.

  • Strong documentation, communication, collaboration, and stakeholder management skills.

  • Demonstrated ownership, attention to detail, and ability to work effectively in a global team environment.

  • Additional cybersecurity experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is a plus.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer – Threat Detection (1401)
Cyber Security Engineer – Threat Detection (1401)

Sharp Decisions • Charlotte (NC)

Hybrid
USD 105,000 - 145,000
Detection Engineer III
Detection Engineer III

OU Health • Oklahoma City (OK)

On-site
USD 110,000 - 140,000
PTO
401(k)
Medical and dental plans
Detection Engineer
Detection Engineer

Binary Defense • United States

On-site
USD 120,000 - 180,000
Threat Detection Engineer - COVERED
Threat Detection Engineer - COVERED

ManpowerGroup Global, Inc. • Charlotte (NC), Town of Norway (WI)

Hybrid
USD 100,000 - 130,000
Flexible work arrangements
Professional growth opportunities
Collaborative working environment
Detection Engineer
Detection Engineer

Ampcus, Inc • Jacksonville (FL)

On-site
Manager, Threat Detection Engineer
Manager, Threat Detection Engineer

Jobtailor • Washington

On-site
USD 140,000 - 190,000
Detection & Mitigation Engineer
Detection & Mitigation Engineer

United States Digital Space LLC • United States

Hybrid
USD 110,000 - 170,000
Equity plan eligibility
Senior Detection & Response Analyst
Senior Detection & Response Analyst

Remote Jobs • United States

On-site
USD 110,000 - 190,000
Detection Engineer - REMOTE
Detection Engineer - REMOTE

Binary Defense • Houston (TX)

On-site
USD 110,000 - 150,000
Remote-friendly work environment
Training opportunities
401k match
+1
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2