Lead Detection Engineer, Endpoint ML & SIEM Automation

Jobtailor

New York (NY)

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Jobtailor in New York seeks a senior Detection Engineer to own end-to-end endpoint threat detection, leveraging telemetry, ML, and GenAI-assisted workflows to reduce false positives and accelerate development.

You will design detections on MITRE ATT&CK, mentor engineers, ensure fintech compliance, and collaborate with CSOC, Threat Intelligence, and CI/CD teams to operationalize across the enterprise SIEM.

Qualifications

  • Must have 4+ years in cybersecurity or IT.
  • 4+ years of experience with endpoint logs (Windows Event Logs, Sysmon, EDR telemetry).
  • 2+ years with EDR platforms (CrowdStrike Falcon, SentinelOne, or Microsoft Defender).
  • 4+ years of alert development for threat detection.

Responsibilities

  • Own end-to-end detection coverage for the Endpoint domain from telemetry requirements to high-fidelity alert deployment.
  • Leverage LLMs and ML to automate detection logic, summarize attack chains, reduce false positives, and accelerate detection development.
  • Lead the design, development, and maintenance of Detection-as-Code rules using GenAI-assisted workflows and CI/CD pipelines.
  • Design and build behavioral detections identifying adversary patterns, TTPs, and anomalous endpoint activity.
  • Use MITRE ATT&CK to visualize, prioritize, and close endpoint coverage gaps.
  • Mentor engineers on security concepts, AI-driven workflows, and detection engineering best practices.

Skills

Endpoint security expertise
Threat detection development
Machine learning in security
Mentoring
Communication

Education

Bachelor's Degree

Tools

CrowdStrike Falcon
SentinelOne
Microsoft Defender
Databricks
Apache Spark
CI/CD workflows
YAML-based detection frameworks

Job description

Jobtailor in New York seeks a senior Detection Engineer to own end-to-end endpoint threat detection, leveraging telemetry, ML, and GenAI-assisted workflows to reduce false positives and accelerate development.

You will design detections on MITRE ATT&CK, mentor engineers, ensure fintech compliance, and collaborate with CSOC, Threat Intelligence, and CI/CD teams to operationalize across the enterprise SIEM.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Threat Intelligence & Detection Architect
Senior Threat Intelligence & Detection Architect

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000
Detection Engineer: SIEM/XDR & Cloud Security
Detection Engineer: SIEM/XDR & Cloud Security

Jobtailor • Arizona

On-site
USD 85,000 - 130,000
Threat-Hunting Security Engineer | AI-Driven Defense
Threat-Hunting Security Engineer | AI-Driven Defense

Jobtailor • California (MO)

On-site
USD 140,000 - 190,000
AI-Driven Threat Detection & Incident Response Engineer
AI-Driven Threat Detection & Incident Response Engineer

Jobtailor • California (MO)

On-site
USD 125,000 - 180,000
Endpoint Detection Engineering Lead
Endpoint Detection Engineering Lead

Capital One • Plano (TX)

On-site
USD 179,000 - 205,000
AI-Driven Endpoint Detection Lead
AI-Driven Endpoint Detection Lead

Capital One National Association • McLean (VA)

On-site
USD 197,000 - 225,000
Endpoint Detection Engineering Manager (AI‑Driven)
Endpoint Detection Engineering Manager (AI‑Driven)

Information Technology Senior Management Forum • McLean (VA)

On-site
USD 197,000 - 225,000
ML Detection Engineer
ML Detection Engineer

Arcitix Security • United States

On-site
USD 100,000 - 130,000
Remote SIEM Detection Engineer: Build Detection Excellence
Remote SIEM Detection Engineer: Build Detection Excellence

Mosaec • Northern (KY)

Hybrid
USD 112,000 - 162,000
Unlimited PTO
Work location flexibility
Parental leave (up to 24 weeks)
Senior AI Security Engineer: Threat Analytics & SIEM
Senior AI Security Engineer: Threat Analytics & SIEM

Jobtailor • Washington

On-site
USD 140,000 - 190,000