Detection Engineer: SQL-Based Network Detections (Remote)

Blue Bear Capital

United States

On-site

USD 170,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Blue Bear Capital is seeking a Network Infrastructure & Security Engineer (Detection Engineering) for a remote role in the US. You will write SQL-based detections, shape data collection strategies, and ensure clean integrations with SIEM/EDR stacks while collaborating with a hands-on team.

You will build datasets, validate detections with telemetry, and drive reusable detection content across industries, including financial services and healthcare, in a startup-like environment.

Qualifications

  • 5+ years in network security engineering, detection engineering, or SOC/threat hunting roles, with direct, hands-on experience building detection content.
  • Strong working experience with network telemetry: NetFlow/IPFIX, DNS logs, and PCAP analysis at scale.
  • Demonstrated experience writing detection logic or correlation content (Sigma rules, SIEM correlation rules, or custom SQL-based detections).
  • Proficiency in SQL and comfort working directly in large-scale data platforms or data warehouses.
  • Familiarity with network probe/sensor technologies (Gigamon, NetQuest, or open-source equivalents such as Zeek or Suricata) and the tradeoffs between them.
  • Solid understanding of the MITRE ATT&CK framework and behavioral/statistical anomaly detection methods (baselining, z-score deviation, peer-group analysis).
  • Experience integrating detection output with SIEM/SOAR/EDR platforms (Splunk, Chronicle, Sentinel, CrowdStrike, SentinelOne, or similar).

Responsibilities

  • Write detection logic. Design, write, and maintain SQL-based behavioral detections and anomaly-scoring logic on top of Ocient's engine - lateral movement, C2 beaconing, DNS tunneling, data exfiltration, and low-and-slow attack patterns using rolling 7/30/90-day baselines.
  • Run the technical program day to day. Build, test, tune, and validate detections against real and simulated telemetry, hands-on - not just define requirements for someone else to build.
  • Build the datasets and demo environment. Work with the team building the demo environment to generate the underlying datasets needed to develop and showcase detections and use cases, alongside the broader platform build-out.
  • Make the work reusable. Build detection logic so it generalizes (~90% reusability) across the industries we support - financial services, telecommunications, energy, healthcare, and government - rather than as vertical-specific one-offs.
  • Shape network probe & data collection strategy. Evaluate and help define our approach to high-volume network data capture, including tradeoffs between commercial probes (Gigamon, NetQuest) and lower-cost or open-source alternatives (e.g., Zeek/Suricata-based collection).
  • Keep integrations clean. Make sure detections and enrichment output integrate cleanly with customers' existing SIEM/EDR stack (Splunk, Chronicle, Sentinel, CrowdStrike) so adoption doesn't require a rip-and-replace.
  • Deliver hands-on during customer pilots. Provide hands-on technical delivery during customer proof-of-value pilots - configuring ingestion, tuning baselines, and validating detections against a customer's actual telemetry.
  • Document as you go. Write up detection logic, runbooks, and technical playbooks so the team's detection library is maintainable and transferable as we grow.

Skills

Network security
Detection engineering
SQL proficiency
SIEM integration
Python scripting
Threat hunting
NetFlow/IPFIX

Tools

Gigamon
NetQuest
Zeek
Suricata
Splunk
Chronicle

Job description

Blue Bear Capital is seeking a Network Infrastructure & Security Engineer (Detection Engineering) for a remote role in the US. You will write SQL-based detections, shape data collection strategies, and ensure clean integrations with SIEM/EDR stacks while collaborating with a hands-on team.

You will build datasets, validate detections with telemetry, and drive reusable detection content across industries, including financial services and healthcare, in a startup-like environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Detection Engineer — SQL-Based Network Security
Remote Detection Engineer — SQL-Based Network Security

Ocient • United States

On-site
USD 170,000 - 210,000
Detection Engineer - REMOTE
Detection Engineer - REMOTE

Binary Defense • Houston (TX)

On-site
USD 110,000 - 150,000
Remote-friendly work environment
Training opportunities
401k match
+1
Remote Detection Engineer: Automation & Detections
Remote Detection Engineer: Automation & Detections

Binary Defense • Houston (TX)

On-site
USD 110,000 - 150,000
Remote-friendly work environment
Training opportunities
401k match
+1
Remote Detection Engineer II: Threat Hunting & SOAR
Remote Detection Engineer II: Threat Hunting & SOAR

United States Digital Space LLC • United States

Remote
USD 142,000 - 150,000
Equity grant
Annual refresh grants
Remote-friendly / Flex First
Staff Detection Engineer: SIEM, Cloud & Threat Hunting
Staff Detection Engineer: SIEM, Cloud & Threat Hunting

LinkedIn • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Health and wellness programs
Annual performance bonus
Stock options
+1
Remote Detection Engineering Lead, AI Security
Remote Detection Engineering Lead, AI Security

Madrona Venture Labs • United States

On-site
USD 200,000 - 250,000
Company-paid health insurance
401K with employer match
Self-managed PTO
+1
Detection Engineer, Cloud Security & IR
Detection Engineer, Cloud Security & IR

Intermedia Lab • San Francisco (CA)

On-site
USD 230,000 - 260,000
Competitive cash compensation
Equity
Full benefits
Remote Senior Detection Engineer — SIEM & Telemetry
Remote Senior Detection Engineer — SIEM & Telemetry

Visa Hunt • Cameron Park (CA), Chicago (IL)

Hybrid
USD 120,000 - 180,000
Medical, Dental & Vision
Employer Paid Life Insurance
Disability Insurance
+3
Detection Engineer
Detection Engineer

Ampcus, Inc • Jacksonville (FL)

On-site
USD 90,000 - 130,000
Detections Solutions Architect - Remote, PTO & Equity
Detections Solutions Architect - Remote, PTO & Equity

Doppel • United States

Remote
USD 75,000 - 95,000
Meaningful equity
Remote-first culture
Flexible PTO
+2