Detection & Threat Engineer

Piper Companies

United States

Remote

USD 130,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
401(k)
PTO

Job summary

Piper Companies is seeking a Detection & Threat Engineer to join a leading cybersecurity-focused organization in the United States. The role focuses on building advanced threat detections, enhancing security monitoring, and increasing threat visibility across enterprise environments.

You will write SPL queries from scratch and apply RBA and UEBA techniques to detect evolving threats. You will partner with Threat Hunting, Incident Response, and SOC teams to implement MITRE ATT&CK-aligned use

Qualifications

  • 4+ years of experience in detection/engineering or security operations.
  • Advanced SPL query development from scratch in Splunk.
  • Experience with Risk-Based Alerting (RBA) and UEBA in enterprise security.
  • Experience developing detection logic and use cases within Splunk Enterprise Security.
  • Familiarity with threat actor TTPs and MITRE ATT&CK framework.
  • Experience supporting SOC, Incident Response, or Threat Hunting functions.

Responsibilities

  • Develop and maintain advanced detection content in Splunk Enterprise Security and related security platforms.
  • Write complex SPL queries from scratch to identify threats, suspicious behaviors, and emerging attack techniques.
  • Design, implement, and optimize Risk-Based Alerting (RBA) methodologies to improve detection fidelity and reduce alert fatigue.
  • Leverage UEBA capabilities to identify anomalous user and entity behavior across enterprise environments.
  • Partner with Threat Hunting, Incident Response, and Security Operations teams to improve detection coverage and investigation workflows.
  • Analyze attack patterns and adversary techniques to create proactive detection use cases aligned with the MITRE ATT&CK framework.
  • Continuously tune and enhance alerting logic to improve operational efficiency and threat visibility.
  • Support detection engineering initiatives for cloud, endpoint, identity, and network security technologies.

Skills

SPL queries
RBA
UEBA
Threat detection
Threat hunting
Security engineering
Analytical skills
Communication

Tools

Splunk Enterprise Security
MITRE ATT&CK

Job description

Piper Companies is seeking a Detection & Threat Engineer to join a leading cybersecurity-focused organization. The Detection & Threat Engineer will play a key role in developing advanced threat detections, enhancing security monitoring capabilities, and improving threat visibility across enterprise environments. This position is ideal for a security professional with strong experience writing SPL queries from scratch and hands‑on expertise with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA).

Responsibilities of the Detection & Threat Engineer:
  • Develop and maintain advanced detection content within Splunk Enterprise Security and related security platforms.
  • Write complex SPL queries from scratch to identify threats, suspicious behaviors, and emerging attack techniques.
  • Design, implement, and optimize Risk-Based Alerting (RBA) methodologies to improve detection fidelity and reduce alert fatigue.
  • Leverage UEBA capabilities to identify anomalous user and entity behavior across enterprise environments.
  • Partner with Threat Hunting, Incident Response, and Security Operations teams to improve detection coverage and investigation workflows.
  • Analyze attack patterns and adversary techniques to create proactive detection use cases aligned with the MITRE ATT&CK framework.
  • Continuously tune and enhance alerting logic to improve operational efficiency and threat visibility.
  • Support detection engineering initiatives for cloud, endpoint, identity, and network security technologies.
Qualifications of the Detection & Threat Engineer:
  • 4+ years of experience in Detection Engineering, Threat Detection, Threat Hunting, or Security Engineering.
  • Advanced experience writing SPL queries from scratch in Splunk.
  • Strong hands‑on experience with Risk-Based Alerting (RBA) and User and Entity Behavior Analytics (UEBA).
  • Experience developing detection logic and security use cases within Splunk Enterprise Security.
  • Knowledge of threat actor tactics, techniques, and procedures (TTPs) and the MITRE ATT&CK framework.
  • Experience supporting SOC, Incident Response, or Threat Hunting functions.
  • Familiarity with cloud security, endpoint security, and identity security monitoring.
  • Excellent analytical, troubleshooting, and communication skills.
Compensation for the Detection & Threat Engineer includes:
  • Salary range: $130,000 - $160,000 depending on experience
  • Comprehensive benefits package including medical, dental, vision, 401(k), and PTO

This job opens for applications on 10/06/2026. Applications for this job will be accepted for at least 30 days from the posting date.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Detection & Threat Engineer - 175934
Detection & Threat Engineer - 175934

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+2
Threat Investigator
Threat Investigator

Piper Companies • United States

On-site
USD 120,000 - 180,000
Medical, dental, vision benefits
401(k)
PTO
Threat Hunting Investigator - 176115
Threat Hunting Investigator - 176115

Piper Companies • United States

Remote
USD 140,000 - 165,000
Remote work
Long-term engagement
Threat Investigator - 175638
Threat Investigator - 175638

Piper Companies • United States

Remote
USD 120,000 - 180,000
Medical benefits
Dental benefits
Vision benefits
+1
Threat Hunting Investigator
Threat Hunting Investigator

Piper Companies • United States

Remote
USD 140,000 - 165,000
Medical insurance
Dental insurance
Vision insurance
+2
Incident Response Engineer
Incident Response Engineer

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical, dental, vision
401(k)
PTO
Incident Response Engineer - 175966
Incident Response Engineer - 175966

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical, dental, vision benefits
401(k) plan
Paid time off
Threat Hunting Investigator - 175695
Threat Hunting Investigator - 175695

Piper Companies • United States

Remote
USD 120,000 - 160,000
Health, Vision, Dental
PTO and Paid Holidays
Sick Leave (as required by law)
Threat Detection Engineer - Splunk, UEBA & RBA
Threat Detection Engineer - Splunk, UEBA & RBA

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical
Dental
Vision
+2
Threat Detection Engineer - Splunk & UEBA Expert
Threat Detection Engineer - Splunk & UEBA Expert

Piper Companies • United States

Remote
USD 130,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+2