Remote Detection Engineer: Automation & Detections

Binary Defense

Houston (TX)

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-friendly work environment
Training opportunities
401k match
Medical, dental and vision coverage

Job summary

Binary Defense is seeking an experienced Detection Engineer to join our Detection Engineering team. You’ll be hands-on building, deploying, and maintaining detections across SIEMs, EDRs, and cloud environments.

You will work with detection-as-code, using Python and REST APIs, YAML/Sigma/YARA-L, and collaborate with Threat Intel, Incident Response, and Cloud Security to improve coverage, efficacy, and scalability.

Qualifications

  • 2-5+ years in detection engineering, threat hunting, or incident response.
  • Strong proficiency with Python and REST APIs for interacting with EDR/SIEM platforms and automating detection workflows.
  • Experience writing, tuning, and validating detection logic in Sigma, YARA-L, Splunk SPL, KQL, or XQL.
  • Experience with telemetry sources including Windows Event Logs, Sysmon, firewall/proxy logs, and cloud platform audit logs.
  • Familiarity with MITRE ATT&CK and mapping detections to techniques and choke points.
  • Ability to quickly learn new security technologies and adapt detection strategies.

Responsibilities

  • Design and implement detections using a detection-as-code approach across SIEM (e.g., Splunk, Sentinel, Chronicle) and EDR platforms (e.g., CrowdStrike, Cortex XDR, SentinelOne).
  • Develop and operationalize detection logic in YAML/Sigma/YARA-L, including documentation, tuning, testing, and version control.
  • Leverage APIs to automate rule deployment, validation, and telemetry inspection - reducing reliance on GUIs.
  • Collaborate with Threat Intel, Incident Response, and Cloud Security teams to create threat-informed detections based on real-world attack behaviors.
  • Contribute to threat modeling efforts to identify high-value detection opportunities and coverage gaps.
  • Analyze telemetry sources (e.g., Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.
  • Participate in adversary simulation and detection validation efforts using tools such as Atomic Red Team, Caldera, or custom scripting.
  • Support documentation of detection logic, coverage rationale, and response guidance.
  • Actively contribute to continuous improvement of detection engineering workflows, tooling, and standards.

Skills

Python
REST APIs
Threat hunting
Incident response
Detection engineering
MITRE ATT&CK

Tools

Sigma
YARA-L
Splunk SPL
KQL
XQL
CrowdStrike
Cortex XDR
SentinelOne

Job description

Binary Defense is seeking an experienced Detection Engineer to join our Detection Engineering team. You’ll be hands-on building, deploying, and maintaining detections across SIEMs, EDRs, and cloud environments.

You will work with detection-as-code, using Python and REST APIs, YAML/Sigma/YARA-L, and collaborate with Threat Intel, Incident Response, and Cloud Security to improve coverage, efficacy, and scalability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Detection Engineer: Build, Automate & Detect
Remote Detection Engineer: Build, Automate & Detect

Totem Market Valuations • Houston (TX)

On-site
USD 110,000 - 165,000
Medical, dental and vision coverage
401k match
Flexible remote-friendly environment
+1
Detection Engineer - REMOTE
Detection Engineer - REMOTE

Binary Defense • Houston (TX)

On-site
USD 110,000 - 150,000
Remote-friendly work environment
Training opportunities
401k match
+1
Remote Detection Engineer II: Threat Hunting & SOAR
Remote Detection Engineer II: Threat Hunting & SOAR

United States Digital Space LLC • United States

Remote
USD 142,000 - 150,000
Equity grant
Annual refresh grants
Remote-friendly / Flex First
Security Engineer – Detection & Incident Response
Security Engineer – Detection & Incident Response

United States Digital Space LLC • New York (NY), Washington

On-site
USD 238,000 - 297,000
Health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2
AI-Driven Detection & Response Engineer
AI-Driven Detection & Response Engineer

United States Digital Space LLC • New York (NY)

On-site
USD 140,000 - 200,000
Detection & Response Engineer - AI-Driven Security
Detection & Response Engineer - AI-Driven Security

Triwill Group • New York (NY)

On-site
USD 120,000 - 180,000
Detection & Response Engineer — AI-Driven Security
Detection & Response Engineer — AI-Driven Security

Neura Market • New York (NY)

On-site
USD 140,000 - 210,000
Director of Detection Engineering & Automation Excellence
Director of Detection Engineering & Automation Excellence

TransUnion • Chicago (IL)

Hybrid
USD 168,000 - 282,000
Medical, dental, vision coverage
HSA/FSA options
Life & AD&D insurance
+8
Detection Engineer, Cloud Security & IR
Detection Engineer, Cloud Security & IR

Intermedia Lab • San Francisco (CA)

On-site
USD 230,000 - 260,000
Competitive cash compensation
Equity
Full benefits
Detection & Response Engineer — AI-Driven Security
Detection & Response Engineer — AI-Driven Security

Doist • New York (NY)

On-site
USD 140,000 - 190,000