Piper Companies is seeking a Detection & Threat Engineer to join a leading cybersecurity-focused organization. The Detection & Threat Engineer will play a key role in developing advanced threat detections, enhancing security monitoring capabilities, and improving threat visibility across enterprise environments. This position is ideal for a security professional with strong experience writing SPL queries from scratch and hands‑on expertise with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA).
Responsibilities of the Detection & Threat Engineer:
- Develop and maintain advanced detection content within Splunk Enterprise Security and related security platforms.
- Write complex SPL queries from scratch to identify threats, suspicious behaviors, and emerging attack techniques.
- Design, implement, and optimize Risk-Based Alerting (RBA) methodologies to improve detection fidelity and reduce alert fatigue.
- Leverage UEBA capabilities to identify anomalous user and entity behavior across enterprise environments.
- Partner with Threat Hunting, Incident Response, and Security Operations teams to improve detection coverage and investigation workflows.
- Analyze attack patterns and adversary techniques to create proactive detection use cases aligned with the MITRE ATT&CK framework.
- Continuously tune and enhance alerting logic to improve operational efficiency and threat visibility.
- Support detection engineering initiatives for cloud, endpoint, identity, and network security technologies.
Qualifications of the Detection & Threat Engineer:
- 4+ years of experience in Detection Engineering, Threat Detection, Threat Hunting, or Security Engineering.
- Advanced experience writing SPL queries from scratch in Splunk.
- Strong hands‑on experience with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA).
- Experience developing detection logic and security use cases within Splunk Enterprise Security.
- Knowledge of threat actor tactics, techniques, and procedures (TTPs) and the MITRE ATT&CK framework.
- Experience supporting SOC, Incident Response, or Threat Hunting functions.
- Familiarity with cloud security, endpoint security, and identity security monitoring.
- Excellent analytical, troubleshooting, and communication skills.
Compensation for the Detection & Threat Engineer includes:
- Salary range: $130,000 - $160,000 depending on experience
- Comprehensive benefits package including medical, dental, vision, 401(k), and PTO
This job opens for applications on 10/06/2026. Applications for this job will be accepted for at least 30 days from the posting date.