Detection Engineer - REMOTE

Binary Defense

Houston (TX)

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-friendly work environment
Training opportunities
401k match
Medical, dental and vision coverage

Job summary

Binary Defense is seeking an experienced Detection Engineer to join our Detection Engineering team. You’ll be hands-on building, deploying, and maintaining detections across SIEMs, EDRs, and cloud environments.

You will work with detection-as-code, using Python and REST APIs, YAML/Sigma/YARA-L, and collaborate with Threat Intel, Incident Response, and Cloud Security to improve coverage, efficacy, and scalability.

Qualifications

  • 2-5+ years in detection engineering, threat hunting, or incident response.
  • Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
  • Experience writing, tuning, and validating detection logic in Sigma, YARA-L, Splunk SPL, KQL, or XQL.
  • Experience with telemetry sources including Windows Event Logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
  • Familiarity with MITRE ATT&CK and mapping detections to techniques and choke points.
  • Ability to quickly learn new security technologies and adapt detection strategies.

Responsibilities

  • Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
  • Leverage APIs to automate rule deployment, validation, and telemetry inspection - reducing reliance on GUIs.
  • Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
  • Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
  • Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
  • Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
  • Support documentation of detection logic, coverage rationale, and response guidance.
  • Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Skills

Python
REST APIs
Threat hunting
Incident response
Detection engineering
MITRE ATT&CK

Tools

Sigma
YARA-L
Splunk SPL
KQL
XQL
CrowdStrike
Cortex XDR
SentinelOne

Job description

Job Type

Full-time

Description

Binary Defense is seeking an experienced and motivated Detection Engineer to join our growing Detection Engineering team. You’ll be a hands-on contributor, responsible for building, deploying, and maintaining high-quality detections across a variety of platforms, including SIEMs, EDRs, and cloud environments.

Our team operates detection engineering as code, and we are looking for someone who thrives in a modern, automation-driven environment. You should have a strong grasp of threat modeling, detection choke points, and the ability to abstract away UI dependencies using Python and REST APIs. This is an opportunity to contribute to a mature detection pipeline focused on coverage, efficacy, and scalability.

Responsibilities
  • Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
  • Leverage APIs to automate rule deployment, validation, and telemetry inspection - reducing reliance on GUIs.
  • Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
  • Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
  • Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
  • Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
  • Support documentation of detection logic, coverage rationale, and response guidance.
  • Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.
Requirements
  • 2-5+ years of hands-on experience in detection engineering, threat hunting, or incident response.
  • Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
  • Demonstrated experience writing, tuning, and validating detection logic in at least one of: Sigma, YARA-L, Splunk SPL, KQL, XQL.
  • Experience with telemetry sources including Windows security logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
  • Familiarity with MITRE ATT&CK and how to map detections to adversary techniques and detection choke points.
  • Ability to quickly learn new security technologies and adapt detection strategies accordingly.
  • Comfortable working in a fast-paced environment where threat-driven detection and rapid iteration are the norm.
Preferred
  • Experience with Cortex XDR and/or XSIAM (XQL-based detection and REST API interaction is a major plus).
  • Experience contributing to a detection-as-code pipeline (e.g., Git-based workflows, rule validation, CI/CD).
  • Exposure to multi-tenant or MDR environments and scaling detections across customer environments.
  • Familiarity with Sigma to YARA-L translation, or with detection rule normalization and enrichment workflows.
  • Experience in IR consulting and working across diverse EDR/SIEM stacks.
About Binary Defense

Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.

For more information, visit our website, check out our blog, or follow us on LinkedIn.

Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer
Detection Engineer

Binary Defense • United States

On-site
USD 120,000 - 180,000
Cybersecurity Threat Hunter - REMOTE
Cybersecurity Threat Hunter - REMOTE

Binary Defense • Houston (TX)

Hybrid
USD 95,000 - 150,000
Medical coverage
401k match
Remote-friendly
+1
Cybersecurity Threat Hunter - REMOTE
Cybersecurity Threat Hunter - REMOTE

Totem Market Valuations • Houston (TX)

Hybrid
USD 120,000 - 180,000
Medical, dental and vision coverage
401k match
Remote-friendly environment
+1
Cybersecurity Threat Hunter - REMOTE
Cybersecurity Threat Hunter - REMOTE

Binary-Defense • Houston (TX)

Hybrid
USD 90,000 - 130,000
Remote-friendly environment
401(k) match
Training opportunities
Tier 2 SOC Analyst - REMOTE
Tier 2 SOC Analyst - REMOTE

Binary Defense • Houston (TX)

Hybrid
USD 70,000 - 95,000
Medical, Dental, Vision
401k match
Remote-friendly work environment
+1
Remote Detection Engineer: Automation & Detections
Remote Detection Engineer: Automation & Detections

Binary Defense • Houston (TX)

On-site
USD 110,000 - 150,000
Remote-friendly work environment
Training opportunities
401k match
+1
Detection Engineer III
Detection Engineer III

OU Health • Oklahoma City (OK)

On-site
USD 110,000 - 140,000
PTO
401(k)
Medical and dental plans
Detection and Response Engineer
Detection and Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Digital mental health support
+1
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Washington

On-site
USD 237,000 - 297,000
Comprehensive health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2